9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Description
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerability exists in InvoicePlane 1.7.0 through a chained Local File Inclusion (LFI) and Log Poisoning attack. An authenticated administrator can execute arbitrary system commands on the server by manipulating the `public_invoice_template` setting to include poisoned log files containing PHP code. Version 1.7.1 patches the issue.
AI Analysis
Remote Code Execution (RCE) vulnerability via Local File Inclusion (LFI) and Log Poisoning
Basic Information
ID
CVE-2026-25548
Source
GitHub_M
Published
Feb 18, 2026 at 22:49
Affected Product
Vendor
InvoicePlane
Product
InvoicePlane
Version
<= 1.7.0
Affected Versions
InvoicePlane InvoicePlane <= 1.7.0
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
InvoicePlane
Product
InvoicePlane
Version
1.7.0