๐Ÿ” CVE Alert

CVE-2026-61749

MEDIUM 6.5

InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credential Disclosure

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or label templates can cause WeasyPrint report rendering to retrieve attacker-selected resources through the HTTP and HTTPS URL schemes or the local file URI scheme. The HTML(string=html).write_pdf() path does not provide a restricted url_fetcher, and attach_to_model=True stores the original generated PDF before later processing, allowing fetched local files or internal HTTP response bodies to be recovered from embedded attachments. This enables full-read server-side request forgery, arbitrary local file disclosure including application credentials, and possible compromise of a superuser account. This issue is fixed in version 1.4.0.

CWE CWE-200 CWE-918
Vendor inventree
Product inventree
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for inventree inventree

Be the first to know when new medium vulnerabilities affecting inventree inventree are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

inventree / InvenTree
< 1.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/inventree/InvenTree/security/advisories/GHSA-568x-qh23-wh8g github.com: https://github.com/inventree/InvenTree/pull/12160 github.com: https://github.com/inventree/InvenTree/commit/2b4f3037703bd499e420b6904153f2b66878d61b github.com: https://github.com/inventree/InvenTree/releases/tag/1.4.0