CVE-2026-23491Disclosure(invoiceplane / invoiceplane)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vulnerability exists in the `get_file` method of the `Guest` module's `Get` controller in InvoicePlane up to and including through 1.6.3. The vulnerability allows unauthenticated attackers to read arbitrary files on the server by manipulating the input filename. This leads to the disclosure of sensitive information, including configuration files with database credentials. Version 1.6.4 fixes the issue.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • invoiceplane

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-18); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
invoiceplane

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-18: 1Mentions · 2026-08-25: 1PoC Mentioned / Linked · 2026-08-25: 1Technical Details · 2026-02-18: 1Technical Details · 2026-08-25: 102-1808-25
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-181
Disclosure1
2026-08-251
PoC1
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    PoC

    🚨 CVE-2026-23491 - high 🚨 InvoicePlane <= 1.6.3 - Arbitrary File Read > InvoicePlane through 1.6.3 is vulnerable to an unauthenticated path traversal in the ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-23491 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces an unauthenticated path traversal in InvoicePlane versions up to 1.6.3, includes a link to a projectdiscovery library (likely a PoC), but does not mention active exploitation, patches, or detailed exploit code.

    00001292
    1.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23491 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vulnerability exists in the `get_file` method of … https://www.cve.org/CVERecord?id=CVE-2026-23491

    Post summary

    A path traversal vulnerability was disclosed in InvoicePlane’s get_file method, but no PoC, exploit, patch or active exploitation details were included.

    00000132
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appinvoiceplaneinvoiceplane---

Explore more