
CVE-2026-33531 InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report template engine allows a staff-level use… https://www.cve.org/CVERecord?id=CVE-2026-33531
Post summary
The post announces CVE-2026-33531, describing a path traversal flaw in InvenTree’s report template engine that can be exploited by staff users, and indicates that upgrade to version 1.2.6 resolves the issue.
