InvenTree是InvenTree开源的一个开源库存管理系统。提供强大的低级库存控制和零件跟踪。 InvenTree 0.16.0至1.2.7之前版本存在安全漏洞,该漏洞源于任何认证用户均可通过POST请求为其他用户创建有效的API令牌,可能导致完全API身份验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-35476 | 7.2 HIGH | InvenTree Affected by Privilege Escalation via API |
| CVE-2026-35479 | 6.6 MEDIUM | InvenTree Plugin Installation - Insufficient Permissions |
| CVE-2026-35477 | 5.5 MEDIUM | InvenTree has SSTI in PART_NAME_FORMAT bypasses CVE-2026-27629 fix via {% if part.pk %} sa |
| CVE-2026-39362 | InvenTree has SSRF via Remote Image Download — No IP/Hostname Validation on remote_image U |
No comments yet