Vulnerability  ·  2026-09-28

Penpot MCP server plugin WebSocket bridge binds to all interfaces unauthenticated (single-user mode)

VulnerabilityLow impactGlobalCVE-2026-100868
NVD published on 2026-09-27 (VulnCheck): Penpot before 2.18.0 binds its MCP plugin WebSocket bridge to all interfaces without authentication in single-user mode (CWE-1327; CVSS 6.3 v3.1, adjacent network).
An AI/MCP-connected design tool's browser-plugin bridge becomes an impersonation point: adjacent-network attackers can feed forged tool results to the MCP client, poisoning agent tool output — a contained but real MCP trust-boundary gap in a popular open-source tool.
In single-user mode the MCP server plugin's WebSocket bridge binds to all network interfaces without authentication; an attacker on an adjacent network connects to the WebSocket port, impersonates the Penpot browser plugin, intercepts task payloads, and returns forged results to the MCP client.
penpot < 2.18.0 (MCP server plugin WebSocket bridge; npm @penpot/mcp <= 2.15.4)
Upgrade to Penpot 2.18.0. Advisories: GHSA-22qr-rp27-j9wm / GHSA-ch2q-6x56-qg5r
NVD CVE-2026-100868GitHub Advisory GHSA-22qr-rp27-j9wm
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →