9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Description
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vulnerability exists in the `get_file` method of the `Guest` module's `Get` controller in InvoicePlane up to and including through 1.6.3. The vulnerability allows unauthenticated attackers to read arbitrary files on the server by manipulating the input filename. This leads to the disclosure of sensitive information, including configuration files with database credentials. Version 1.6.4 fixes the issue.
AI Analysis
Unauthenticated path traversal vulnerability in the Guest Controller's get_file method, allowing attackers to read arbitrary files on the server.
Basic Information
ID
CVE-2026-23491
Source
GitHub_M
Published
Feb 18, 2026 at 19:52
Modified
Feb 18, 2026 at 20:50
Affected Product
Vendor
InvoicePlane
Product
InvoicePlane
Version
< 1.6.4
Affected Versions
InvoicePlane InvoicePlane < 1.6.4
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
InvoicePlane
Product
InvoicePlane
Version
< 1.6.4