GHSA-hm3w-7xgf-hfwfMediumCVSS 6.3
Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces...
🔗 CVE IDs covered (1)
📋 Description
Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forged results to the MCP client.
🔗 References (8)
- https://github.com/penpot/penpot/security/advisories/GHSA-22qr-rp27-j9wm
- https://github.com/penpot/penpot/security/advisories/GHSA-ch2q-6x56-qg5r
- https://nvd.nist.gov/vuln/detail/CVE-2026-100868
- https://github.com/penpot/penpot/commit/b5274a44766d095247037be18c1d1918ac67ddeb
- https://github.com/penpot/penpot
- https://github.com/penpot/penpot/blob/1d2c37e52c733f74017d90b0fd1ae2d074a5c33d/mcp/packages/server/src/PluginBridge.ts#L52
- https://www.vulncheck.com/advisories/penpot-before-2.18.0-unauthenticated-websocket-access-via-mcp-bridge
- https://github.com/advisories/GHSA-hm3w-7xgf-hfwf