Sketch is a design and prototyping application with a focused vulnerability footprint centered on file-handling and upload mechanisms. The observed weakness classes reflect input-validation and file-type control gaps typical of applications that process user-supplied design assets. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sketch over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40531CRITICAL Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This | Sep 6, 2021 | 9.8 | 49 | NO | NO |
CVE-2002-2047HIGH The file preview functionality in Sketch 0.6.12 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an encapsulated Postsc | Dec 31, 2002 | 10.0 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sketch.
Media articles that mention a CVE ID that affects a product developed by Sketch — matched by CVE ID, not by vendor name.