External risk intelligence

Penpot SVG Export Command Injection Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-105691

Penpot is an open-source design and prototyping platform commonly deployed as a web-based service. The vulnerability is explicitly triggered via public share links to design files, which are intended for external access, making the attack surface readily reachable via the internet in standard deployments.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in the Penpot design and prototyping platform that could allow unauthorized command execution on the service. The flaw lies within the SVG export functionality, where specially crafted files, whether edited by a user or accessed via a public share link, can trigger the execution of malicious commands with the exporter service's privileges. This could have significant implications for the confidentiality, integrity, and availability of the Penpot service and any data it manages.

  • Malicious file exports can run unauthorized commands.
  • Critical flaw impacts design platform service security.
  • Confirm Penpot relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by manipulating the fill color of a text object within a design file. This manipulation, when combined with the SVG export feature or by sharing a malicious file via a public link, allows for the execution of arbitrary commands on the server where the exporter service runs.

  • Requires ability to edit files or share via public link.
  • Triggered by exporting a malicious SVG file.
  • Risk of unauthorized command execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an authenticated user or an unauthenticated user with a public share link to a malicious file to execute arbitrary commands on the server running the Penpot exporter service. This could occur when a specially crafted SVG file is uploaded and then exported, or when a malicious SVG file is accessed via a public share link and exported. The potential impact includes unauthorized access and manipulation of the Penpot service.

  • Service-level command execution.
  • Triggered by SVG export.
  • Compromise of the exporter service.

Operational Fix

Recommended remediation, mitigation, and detection steps

Platform and application owners are likely responsible for addressing this vulnerability in the Penpot design and prototyping platform. The first practical step is to identify all Penpot instances, determine their reachability and business criticality, and locate the accountable owner to plan remediation.

  • Identify Penpot instances and owners.
  • Verify external reachability and business impact.
  • Coordinate vendor action or internal updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Penpot?

Penpot is an open-source platform used for interface design and prototyping. It allows teams to collaborate on visual projects in a web-based environment. Because it processes design files that may include various visual assets and complex formatting, it requires robust mechanisms to handle file exports, such as converting designs into SVG format for use outside the application.

What does CVE-2026-105691 mean?

This CVE describes a command injection vulnerability, classified as CWE-78. This weakness occurs when an application improperly constructs system commands using untrusted input. In this case, Penpot's SVG exporter takes text fill-color values from a design file and passes them directly to a system function. If an attacker inserts malicious shell characters into that color field, the server may execute unintended commands with the privileges of the exporter service.

How is this vulnerability triggered?

The flaw is triggered when the system processes an SVG export for a file containing a manipulated fill-color value. This can happen if an authorized user edits a file or if an attacker uses a public share link to a malicious file. Importantly, simply viewing or hosting the file is not enough; the specific action of triggering the export process is required for the command injection to occur.

Is my Penpot instance at risk?

According to Halo Surface Signal, this vulnerability is likely to affect Penpot deployments because the software is commonly used as a web-based service. Since the flaw can be triggered through public share links—a feature designed for external access—deployments that are reachable via the internet should be considered at higher risk, as they allow access to the vulnerable export functionality.

How do I fix this security issue?

The primary response is to update your Penpot software to version 2.18.0 or later, which contains the fix for this vulnerability. Before updating, identify all running instances of Penpot within your organization to ensure comprehensive coverage. Coordinate with your team to verify the update schedule and confirm that the upgrade is successfully applied to all affected service environments.

References