CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100868

MEDIUMCVSS 6.3NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forge

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100868 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100868

MEDIUMCVSS 6.3NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forge

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]