CVE-2026-45805

HIGH

Penpot < 2.15.0 MCP REPL - Unauthenticated Remote Code Execution

Title source: manual
STIX 2.1

Description

Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/server/src/ReplServer.ts bound the ReplServer to 0.0.0.0:4403 and exposed an unauthenticated /execute endpoint that passed the code field to PluginBridge.executePluginTask(), allowing anyone on the network to execute JavaScript on the server. This issue is fixed in version 2.15.0.

References (4)

Core 4

Scores

CVSS v3 8.8
EPSS 0.0023
EPSS Percentile 13.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-749
Status published
Products (1)
penpot/penpot < 2.15.0
Published Jul 15, 2026
Tracked Since Jul 15, 2026