PatchSiren cyber security CVE debrief
CVE-2026-45806 penpot CVE debrief
Penpot, an open-source design tool for design and code collaboration, had a vulnerability in versions before 2.15.0 that allowed authenticated file editors to access internal-only endpoints through the remote image import feature. This issue was due to insufficient destination filtering in the shared HTTP client. Users of Penpot, especially those with authenticated access to file editing features, should be aware of this vulnerability and ensure they are running version 2.15.0 or later to mitigate the risk. The CVE record was published on 2026-07-15T16:16:45.927Z and last modified on 2026-07-20T16:17:00.887Z. The NVD entry is currently Deferred.
- Vendor
- penpot
- Product
- Unknown
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-15
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-07-15
- Advisory updated
- 2026-07-20
Who should care
Users of Penpot, especially those with authenticated access to file editing features, should be aware of this vulnerability and ensure they are running version 2.15.0 or later to mitigate the risk. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess the impact of this vulnerability on their environments and take appropriate action.
Technical summary
The vulnerability in Penpot before version 2.15.0 allows an authenticated file editor to access internal-only endpoints through the remote image import feature. This is due to the lack of destination filtering in the shared HTTP client used by the media/download-image function. The issue arises from the user-controlled URL being passed from the frontend into the backend RPC method without proper filtering, enabling potential unauthorized access to internal endpoints.
Defensive priority
High
Recommended defensive actions
- Upgrade to Penpot version 2.15.0 or later
- Restrict access to file editing features to trusted users
- Monitor for suspicious activity related to remote image imports
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-07-15T16:16:45.927Z and last modified on 2026-07-20T16:17:00.887Z. The NVD entry is currently Deferred. This vulnerability affects Penpot, an open-source design tool for design and code collaboration. The remote image import feature in Penpot versions before 2.15.0 allows an authenticated file editor to access internal-only endpoints due to the lack of destination filtering in the shared HTTP client used by the media/download-image function. Users should verify their current version and update to 2.15.0 or later to mitigate this risk. Additional verification steps include reviewing access controls for file editing features and monitoring for suspicious activity related to remote image imports.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-15T16:16:45.927Z and has not been modified since then. The NVD entry is currently Deferred.