HIGH8.8npm
GHSA-22qr-rp27-j9wm· CVE-2026-45805PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE
Modified: 9/28/2026
package
pkg:npm/%40penpot/mcp
PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE
Modified: 9/28/2026