Penpot disclosed and fixed CVE-2026-45805, a high-severity remote code execution flaw in its MCP component affecting versions earlier than 2.15.0. The issue stemmed from ReplServer.ts binding a REPL service to 0.0.0.0:4403 and exposing an unauthenticated /execute endpoint that passed attacker-controlled input to PluginBridge.executePluginTask(), allowing arbitrary JavaScript execution by anyone with network access. The CVE was assigned CWE-749 and a CVSS v3.1 score reflecting high impact to confidentiality, integrity, and availability.
Project fixes moved the MCP REPL binding to localhost and shipped alongside broader security hardening in Penpot, including protections against SSRF, stored XSS, CSS injection through font family validation, and incorrect invitation token handling during registration. The vulnerability record also notes proof-of-concept exploitation metadata and links to the fixing commit, release notes, issue tracker, and GitHub security advisory, with remediation available in Penpot 2.15.0.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
The vulnerability was cataloged as CVE-2026-45805, affecting Penpot versions earlier than 2.15.0, with details describing unauthenticated code execution via the MCP REPL server. The CVE record was received on July 15, 2026 and modified the same day to add a GitHub advisory reference and SSVC metadata.
Penpot fixed a vulnerability in its MCP component by changing the REPL server behavior so it no longer exposed an unauthenticated /execute endpoint bound to 0.0.0.0, addressing remote JavaScript execution on the server. The fix is referenced in Penpot release materials and code changes associated with version 2.15.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.