Описание
Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/server/src/ReplServer.ts bound the ReplServer to 0.0.0.0:4403 and exposed an unauthenticated /execute endpoint that passed the code field to PluginBridge.executePluginTask(), allowing anyone on the network to execute JavaScript on the server. This issue is fixed in version 2.15.0.
Ссылки
EPSS
Процентиль: 14%
0.00229
Низкий
8.8 High
CVSS3
Дефекты
CWE-749
Связанные уязвимости
CVSS3: 8.8
github
2 месяца назад
PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE
EPSS
Процентиль: 14%
0.00229
Низкий
8.8 High
CVSS3
Дефекты
CWE-749