CVE-2026-105691 - Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color
CVE ID :CVE-2026-105691 Published : Oct. 5, 2026, 8:17 p.m. | 1 hour, 11 minutes ago Description :Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and...