What happened
NVD published on 2026-09-27 (VulnCheck): Penpot before 2.18.0 binds its MCP plugin WebSocket bridge to all interfaces without authentication in single-user mode (CWE-1327; CVSS 6.3 v3.1, adjacent network).
Why it matters
An AI/MCP-connected design tool's browser-plugin bridge becomes an impersonation point: adjacent-network attackers can feed forged tool results to the MCP client, poisoning agent tool output — a contained but real MCP trust-boundary gap in a popular open-source tool.
Attack vector
In single-user mode the MCP server plugin's WebSocket bridge binds to all network interfaces without authentication; an attacker on an adjacent network connects to the WebSocket port, impersonates the Penpot browser plugin, intercepts task payloads, and returns forged results to the MCP client.
Affected systems
penpot < 2.18.0 (MCP server plugin WebSocket bridge; npm @penpot/mcp <= 2.15.4)
Mitigation
Upgrade to Penpot 2.18.0. Advisories: GHSA-22qr-rp27-j9wm / GHSA-ch2q-6x56-qg5r