GHSA-hm3w-7xgf-hfwfMediumCVSS 6.3

Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces...

Published
September 27, 2026
Last Modified
September 27, 2026

🔗 CVE IDs covered (1)

📋 Description

Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forged results to the MCP client.

🔗 References (8)