CVE-2026-61749
6.5InvenTree · InvenTree
InvenTree versions prior to 1.4.0 contain a vulnerability allowing privileged users to perform Server-Side Request Forgery and disclose local files via manipulated report or label templates.
Executive summary
A vulnerability in InvenTree versions prior to 1.4.0 allows authenticated staff users to bypass security controls to access sensitive server files and internal network resources.
Vulnerability
The application fails to restrict URL fetching during WeasyPrint report rendering, enabling authenticated users with report creation privileges to perform Server-Side Request Forgery and unauthorized local file disclosure.
Business impact
Successful exploitation of this flaw can lead to the exposure of sensitive system files, application credentials, and internal network data. Given the CVSS score of 6.5, this vulnerability represents a significant risk to organizational confidentiality and integrity, particularly because it could facilitate the compromise of administrative or superuser accounts.
Remediation
Immediate Action: Update the InvenTree installation to version 1.4.0 or later to implement the required URL fetching restrictions.
Proactive Monitoring: Review audit logs for unusual report generation activity or attempts to access non-standard local file paths by staff users.
Compensating Controls: Restrict report and label template creation capabilities to a strictly limited group of highly trusted users until the software update can be applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a clear risk of lateral movement and privilege escalation for organizations relying on InvenTree. Administrators should prioritize the deployment of version 1.4.0 immediately to eliminate the underlying insecure template processing mechanism.
More InvenTree CVEs
History
- Analyst report written