CVE-2026-47666 – Penpot

CVSS 7.6 IMPORTANT Zero Day – Immediate Deployment

“Malicious shared content can execute in collaborators’ browsers and expose trusted Penpot sessions.”

Penpot fixes two High-severity stored cross-site scripting vulnerabilities. CVE-2026-47665 allows a team member to inject malicious HTML through file comments, causing JavaScript to execute when another collaborator opens the comments panel. The CVSS score is 8.7, which is High severity.

CVE-2026-47666 allows malicious custom font-family names to break out of generated style content and execute JavaScript when affected files are rendered. The CVSS score is 7.6, which is High severity. Public proof-of-concept material is available for both vulnerabilities. Penpot 2.15.3 contains the fixes.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
CWE Classification
CWE-79
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.