Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/server/src/ReplServer.ts bound the ReplServer to 0.0.0.0:4403 and exposed an unauthenticated /execute endpoint that passed the code field to PluginBridge.executePluginTask(), allowing anyone on the network to execute JavaScript on the server. This issue is fixed in version 2.15.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains README.md (746 bytes) and penpot.sh (5,999 bytes). The README claims CVE-2026-45805 affects Penpot below 2.15.0 and shows a POST to /execute evaluating Node.js code. The standalone Bash script parses a target URL, a direct command or one of five reverse-shell types, and an optional callback port. It probes the endpoint, generates JavaScript using child_process.execSync, writes a temporary JSON body, submits it with curl, prints the response, and attempts cleanup. Embedded payloads use JavaScript, shell commands, Python, and Perl; no exploit framework is present. Important reliability defects prevent treating this as a verified working exploit. generate_payload writes status messages to stdout, and PAYLOAD=$(generate_payload) captures those messages along with the JavaScript. The JSON escaping handles backslashes and quotes but not the captured literal newlines/control characters, producing invalid JSON in ordinary execution. Direct commands are also interpolated without JavaScript-string escaping. The Perl template contains backslash/dollar escaping that can expand unset Bash variables under set -u. The Bash reverse-shell command relies on Bash-specific redirection although execSync normally runs its command through /bin/sh. Reverse shells execute synchronously and can hold the HTTP request open. The GET probe checks curl transport success, not vulnerability or HTTP status, and the script does not validate exploitation success. There is no supporting vulnerable application code, patch analysis, or captured execution evidence confirming the claimed Penpot endpoint, affected versions, or CVE association. The removal of /tmp/f is consistent with FIFO setup rather than evidence of a fake destructive exploit. No fixed public callback or exfiltration host appears. Repository URL, git reference, and archive size were not supplied; their fields use empty strings and zero as unknown-value placeholders. The supplied file sizes total 6,745 bytes, which is not an archive-size measurement.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.