PT-2026-1550 · Unknown · Invoice Ninja

·

CVE-2026-0649

·

Published

2026-01-07

·

Updated

2026-01-07

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions invoiceninja versions prior to 5.12.38
Description A security issue exists in invoiceninja. The issue involves server-side request forgery (SSRF) stemming from manipulation of the company logo argument within the copy function of the /app/Jobs/Util/Import.php file, part of the Migration Import component. This allows for remote exploitation. The details of the issue have been publicly disclosed.
Recommendations Update invoiceninja to version 5.12.38 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-0649

Affected Products

Invoice Ninja