VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-17613

CVE-2026-17613: Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated

Published Aug 5, 2026 CVSS 7.5

Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.

Affected AI Products

data poisoning
Get the weekly digest. Every Monday: top AI security stories of the week. Free.