AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-17613

HIGH · CVSS 7.5 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability in Penpot's ::import-binfile RPC command allows any authenticated user to exploit the lack of authorization on the optional file-id parameter, leading to unauthorized file overwrites on the server. This could result in full data exfiltration and data poisoning through WebSocket event subscriptions. Organizations using Penpot should prioritize this issue to mitigate the risk of data compromise and integrity loss.

CVE
CVE-2026-17613
Severity
HIGH
CVSS
7.5
EPSS
0.42%

Original NVD Description

Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.