Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pj8j-p4g4-4vw8 | Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs |
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is later rendered into an invoice PDF, such as `Customer.invoiceText`, the server-side PDF renderer will fetch remote image URLs embedded in Markdown image syntax. This allows the application server to issue outbound requests to attacker-controlled or internal targets during PDF rendering. The behavior can be used for internal network probing, server-side reachability checks, and potentially follow-on exploitation depending on deployment environment and accessible internal services. Version 2.58.0 patches the issue. | |
| Title | Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-11T21:08:47.179Z
Reserved: 2026-06-01T22:03:19.641Z
Link: CVE-2026-49865
No data.
Status : Received
Published: 2026-09-11T21:17:10.783
Modified: 2026-09-11T21:17:10.783
Link: CVE-2026-49865
No data.
OpenCVE Enrichment
Updated: 2026-09-12T12:00:12Z
Github GHSA