Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-45805

16 дней назад

Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/server/src/ReplServer.ts bound the ReplServer to 0.0.0.0:4403 and exposed an unauthenticated /execute endpoint that passed the code field to PluginBridge.executePluginTask(), allowing anyone on the network to execute JavaScript on the server. This issue is fixed in version 2.15.0.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22qr-rp27-j9wm

2 месяца назад

PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-45805

Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/server/src/ReplServer.ts bound the ReplServer to 0.0.0.0:4403 and exposed an unauthenticated /execute endpoint that passed the code field to PluginBridge.executePluginTask(), allowing anyone on the network to execute JavaScript on the server. This issue is fixed in version 2.15.0.

CVSS3: 8.8
0%
Низкий
16 дней назад
github логотип
GHSA-22qr-rp27-j9wm

PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE

CVSS3: 8.8
0%
Низкий
2 месяца назад

Уязвимостей на страницу