CVE-2026-17613
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Aug 05, 2026
Vendor
unknown
Description
Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.