CyberRota Analysis
AI-GeneratedThe vulnerability in Penpot's ::import-binfile RPC command allows any authenticated user to exploit the lack of authorization on the optional file-id parameter, leading to unauthorized file overwrites on the server. This could result in full data exfiltration and data poisoning through WebSocket event subscriptions. Organizations using Penpot should prioritize this issue to mitigate the risk of data compromise and integrity loss.
Original NVD Description
Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.