Junglewise Threat Intelligence

CVE-2026-45805: Penpot MCP unauthenticated RCE in ReplServer

CVE-2026-45805 · Severity: high · CVSS 8.8 · Published 2026-07-15

Technologies: Penpot Mcp. Vendors: Penpot, npm.

Executive brief

PenPot's MCP (Model Context Protocol) REPL server is a development tool that executes JavaScript code for AI-assisted design workflows. The server listens on all network interfaces without authentication, allowing anyone on the network to remotely execute arbitrary code, read sensitive files, dump credentials, and compromise the entire system.

Technical details

The vulnerability is a combination of two flaws in ReplServer.ts: (1) The Express HTTP server is bound to all interfaces (0.0.0.0:4403) due to a missing hostname argument in the listen() call—Express defaults to 0.0.0.0 when no host is specified; (2) the POST /execute endpoint accepts arbitrary JavaScript code in the request body with zero authentication checks and executes it via PluginBridge.executePluginTask(). An attacker needs only network access to the port and can invoke the endpoint with a POST request containing JSON with a "code" field. This enables full code execution as the server process, allowing file system access, command execution, and environment variable exfiltration (often containing database credentials and API keys). The vulnerability affects all versions prior to 2.15.0; a prior partial fix (#8683, #8686) only addressed the main PenpotMcpServer but overlooked ReplServer.ts.

Affected products

  • PenPot @penpot/mcp all versions before 2.15.0

Timeline

  • 2026-05-19: disclosed: Vulnerability disclosed via GitHub security advisory GHSA-22qr-rp27-j9wm
  • 2026-05-19: patched: Fixed in version 2.15.0

References