HIGH
penpot
CVE published 2026-07-15
CVE-2026-45806
Penpot, an open-source design tool for design and code collaboration, had a vulnerability in versions before 2.15.0 that allowed authenticated file editors to access internal-only endpoints through the remote image import feature. This issue was due to insufficient destination filtering in the shared HTTP client. Users of Penpot, especially those with authenticated access to file editing features, should [truncated]