kaleidos CVE Vulnerabilities & CVE List (1)

Products (CPE): — CVEs: 1

kaleidos vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to kaleidos, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 11 of 1 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-26202 Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user can read arbitrary files from the server by supplying a local file path (e.g. `/etc/passwd`) as a font data chunk in the `create-font-variant` RPC endpoint, resulting in the file contents being stored and retrievable as a "font" asset. This is an arbitrary file read vulnerability. Any authenticated user with team edit permissions can read arbitrary files accessible to the Penpot [email protected] 7.5 0.06% 2026-02-19 2026-02-20
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence