Kaleidos maintains Penpot, an open-source design and prototyping platform, with a modest vulnerability footprint centered on file-handling and path-control issues such as external control of file names and path-traversal weaknesses. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kaleidos over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-26202HIGH Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user can read arbitrary files from the server by supplying a local | Feb 19, 2026 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kaleidos.
Media articles that mention a CVE ID that affects a product developed by Kaleidos — matched by CVE ID, not by vendor name.