What is CVE-2026-17613?
A missing authorization check on the 'file-id' parameter in Penpot's ::import-binfile RPC command allows any authenticated user to overwrite server files. Additionally, subscribing to WebSocket events enables full data exfiltration and data poisoning. Users should urgently update Penpot to the latest version.
Azərbaycanca: Penpot dizayn platformasının ::import-binfile RPC əmrində 'file-id' parametrində avtorizasiya yoxlanışı zəifliyi aşkarlanıb. İstənilən autentifikasiya olunmuş istifadəçi serverdə faylları üzərinə yaza, WebSocket hadisələrinə abunə olaraq tam məlumat sızması və zəhərlənməsi həyata keçirə bilər. Dərhal Penpot-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
Through which RPC command in Penpot can any authenticated user overwrite files on the server?
This vulnerability is exploited via the ::import-binfile RPC command due to a missing authorization check on the 'file-id' parameter. Any authenticated user can leverage this to overwrite files on the server, and by subscribing to WebSocket events, they can perform full data exfiltration and data poisoning.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.