CVE-2026-105687
EUVD-2026-9270505.10.2026, 20:17
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to remove any member other than themselves but does not protect the team owner. A non-owner administrator can delete the owner's team-profile-rel membership and lock the owner out of the team and its projects, files, fonts, and media. This issue is fixed in version 2.18.0.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration