This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+1 more
ReleasePort's take
Light signalPenpot 2.15.3 fixes Plugin API token method failures and sanitizes comment rendering and custom font family names.
Why it matters: Upgrade to Penpot 2.15.3 immediately to resolve the Plugin API schema validation bug and mitigate potential XSS risks from unsanitized comments or fonts.
Summary
AI summaryFixed Plugin API token methods failing with schema validation error.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Bugfix | Medium |
Fix Plugin API token methods failing with schema validation error on PRO. Fix Plugin API token methods failing with schema validation error on PRO. Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Bugfix | Medium |
Sanitize comment content on rendering. Sanitize comment content on rendering. Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Bugfix | Medium |
Sanitize font family names on custom uploaded fonts. Sanitize font family names on custom uploaded fonts. Source: llm_adapter@2026-05-21 Confidence: high |
— |
Full changelog
:bug: Bugs fixed
- Fix Plugin API token methods failing with schema validation error on PRO Github #9641
(PR: #9632) - Sanitize comment content on rendering Github #9642
(PR: #9605) - Sanitize font family names on custom uploaded fonts Github #9643
(PR: #9601)
Security Fixes
- Sanitized comment content and font family names to prevent injection attacks
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]