InvenTree 是一个开源的库存管理系统。在 1.4.0 版本之前, 和 接口未将 和 的查询集(querysets)限制为关联的 的所有者。任何经过身份验证的用户(包括未分配角色的账户)都可以提供其他用户的导入会话标识符,并获取该会话的 、 字段以及其列映射信息。这导致跨用户暴露了为导入而暂存的数据完整内容。尽管 InvenTree 的威胁模型将经过身份验证的实例用户视为可信用户,此问题仍构成了安全风险。该漏洞已在 1.4.0 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61749 | 6.5 MEDIUM | InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credentia |
| CVE-2026-61744 | 6.5 MEDIUM | InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data wit |
| CVE-2026-61746 | 5.3 MEDIUM | InvenTree: Plugin-settings GET endpoints are readable without authentication |
| CVE-2026-61748 | 4.3 MEDIUM | InvenTree: Report/Label print endpoints ignore per-model permissions |
| CVE-2026-61745 | 4.3 MEDIUM | InvenTree: Missing authorization on machine restart endpoint allows any authenticated user |
No comments yet