Package impact

npm npm / @penpot/mcp

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-45805 high 8.0 10d ago PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE