{"id":"CVE-2026-17613","published":"2026-08-05T15:16:40.003","lastModified":"2026-08-05T16:16:53.933","description":"Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://github.com/penpot/penpot/releases/tag/2.17.0","tags":[]},{"url":"https://penpot.app/","tags":[]},{"url":"https://vokecyber.com/blog/cve-2026-17613-penpot-cross-team-file-takeover","tags":[]},{"url":"https://vokecyber.com/research/cve-2026-17613-penpot-cross-team-file-takeover","tags":[]},{"url":"https://vokecyber.com/research/cve-2026-17613-penpot-cross-team-file-takeover","tags":[]}],"exploitRefs":[{"url":"https://github.com/penpot/penpot/releases/tag/2.17.0","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows any authenticated user to overwrite files and subscribe to WebSocket events, enabling data exfiltration and poisoning.","exploitability":"Exploitation requires an authenticated session but no specific permissions beyond basic authentication.","blast_radius":"If exploited, the impact could be severe, allowing full control over server files and real-time event manipulation.","remediation":"Implement proper authorization checks for the ::import-binfile RPC command’s file-id parameter.","tags":["auth-bypass","data-exfiltration","websockets","file-overwrite"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:59:43.752Z"}}