InvenTree 是一个开源的库存管理系统。在 1.4.0 版本之前,PluginSettingList、PluginAllSettingList 和 PluginSettingDetail 在设置 GlobalSettingsPermissions 时,未包含项目默认的全局设置端点所使用的 IsAuthenticated 权限。由于 GlobalSettingsPermissions 对安全方法(如 GET 请求)返回 true,而 AuthRequiredMiddleware 又排除了以 /api/ 开头的路
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61749 | 6.5 MEDIUM | InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credentia |
| CVE-2026-61744 | 6.5 MEDIUM | InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data wit |
| CVE-2026-61748 | 4.3 MEDIUM | InvenTree: Report/Label print endpoints ignore per-model permissions |
| CVE-2026-61747 | 4.3 MEDIUM | InvenTree: Authenticated IDOR in the data-import API exposes other users' imported rows (` |
| CVE-2026-61745 | 4.3 MEDIUM | InvenTree: Missing authorization on machine restart endpoint allows any authenticated user |
No comments yet