📄 Penpot Server-Side Request Forgery_PACKETSTORM:224373
Penpot's remote image import let an authenticated file editor turn a normal media convenience feature into backend-origin server-side request forgery because attacker-controlled URLs crossed into a redirect-following server fetch path without...