InvenTree 是一个开源的库存管理系统。在 1.4.0 版本之前,具有特权的员工用户如果能够创建报告或标签模板,可能会利用 WeasyPrint 的报告渲染功能,通过 HTTP 或 HTTPS URL 方案以及本地文件 URI 方案,检索由攻击者选定的资源。 代码路径未提供受限的 ,并且当 时,系统会在后续处理之前存储原始生成的 PDF 文件,这使得从嵌入的附件中恢复所获取的本地文件或内部 HTTP 响应体成为可能。由此可导致完全读取型的服务端请求伪造(SSRF)、任意本地文件泄露(包括应用凭据),并可能导致
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61744 | 6.5 MEDIUM | InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data wit |
| CVE-2026-61746 | 5.3 MEDIUM | InvenTree: Plugin-settings GET endpoints are readable without authentication |
| CVE-2026-61748 | 4.3 MEDIUM | InvenTree: Report/Label print endpoints ignore per-model permissions |
| CVE-2026-61747 | 4.3 MEDIUM | InvenTree: Authenticated IDOR in the data-import API exposes other users' imported rows (` |
| CVE-2026-61745 | 4.3 MEDIUM | InvenTree: Missing authorization on machine restart endpoint allows any authenticated user |
No comments yet