CVE-2026-100868EPSS p15.8%

CVE-2026-100868CVE-2026-100868

Description

Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forged results to the MCP client.

Scoring

CVSS 6.3 ()
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS0.26% probability of exploitation · percentile 15.8% · 2026-10-05T12:00:23Z
Last modified2026-09-30
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.