CVE-2026-47666 – Penpot
CVSS 7.6
IMPORTANT
Zero Day – Immediate Deployment
“Malicious shared content can execute in collaborators’ browsers and expose trusted Penpot sessions.”
Penpot fixes two High-severity stored cross-site scripting vulnerabilities. CVE-2026-47665 allows a team member to inject malicious HTML through file comments, causing JavaScript to execute when another collaborator opens the comments panel. The CVSS score is 8.7, which is High severity.
CVE-2026-47666 allows malicious custom font-family names to break out of generated style content and execute JavaScript when affected files are rendered. The CVSS score is 7.6, which is High severity. Public proof-of-concept material is available for both vulnerabilities. Penpot 2.15.3 contains the fixes.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- Required
- CWE Classification
- CWE-79
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.