Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-61749— InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credential Disclosure

Quick assessment

Affected
inventree InvenTree
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

InvenTree 是一个开源的库存管理系统。在 1.4.0 版本之前,具有特权的员工用户如果能够创建报告或标签模板,可能会利用 WeasyPrint 的报告渲染功能,通过 HTTP 或 HTTPS URL 方案以及本地文件 URI 方案,检索由攻击者选定的资源。 代码路径未提供受限的 ,并且当 时,系统会在后续处理之前存储原始生成的 PDF 文件,这使得从嵌入的附件中恢复所获取的本地文件或内部 HTTP 响应体成为可能。由此可导致完全读取型的服务端请求伪造(SSRF)、任意本地文件泄露(包括应用凭据),并可能导致

CVSS 6.5 · Medium EPSS 0.48% · P39

Affected Version Matrix 1

VendorProduct Version RangeStatus
inventree InvenTree < 1.4.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61749

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credential Disclosure
Source: CVE Program / CVE List V5
Vulnerability Description
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or label templates can cause WeasyPrint report rendering to retrieve attacker-selected resources through the HTTP and HTTPS URL schemes or the local file URI scheme. The HTML(string=html).write_pdf() path does not provide a restricted url_fetcher, and attach_to_model=True stores the original generated PDF before later processing, allowing fetched local files or internal HTTP response bodies to be recovered from embedded attachments. This enables full-read server-side request forgery, arbitrary local file disclosure including application credentials, and possible compromise of a superuser account. This issue is fixed in version 1.4.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
inventree InvenTree < 1.4.0 -

II. Public POCs for CVE-2026-61749

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-61749

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-61749 (2)

Other References for CVE-2026-61749 (2)

Same Patch Batch · inventree · 2026-09-21 · 6 CVEs total

CVE-2026-61744 6.5 MEDIUM InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data wit
CVE-2026-61746 5.3 MEDIUM InvenTree: Plugin-settings GET endpoints are readable without authentication
CVE-2026-61748 4.3 MEDIUM InvenTree: Report/Label print endpoints ignore per-model permissions
CVE-2026-61747 4.3 MEDIUM InvenTree: Authenticated IDOR in the data-import API exposes other users' imported rows (`
CVE-2026-61745 4.3 MEDIUM InvenTree: Missing authorization on machine restart endpoint allows any authenticated user

IV. Related Vulnerabilities

V. Comments for CVE-2026-61749

No comments yet


Leave a comment