top of page
perceptive_background_267k.jpg

Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by p…

Published:

29 July 2026 at 22:00:00

Alert date:

30 July 2026 at 20:07:35

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Zero-Day Vulnerabilities

Leantime version 3.6.2 contains a server-side request forgery (SSRF) and local file inclusion (LFI) vulnerability in the Blueprints::import() method. The flaw arises from passing unsanitized user-supplied filenames directly to PHP's file_get_contents() function without path validation. Authenticated attackers can exploit this via the JSON-RPC API endpoint by submitting crafted filenames containing URL wrappers or path traversal sequences. Successful exploitation allows attackers to access cloud metadata services or read arbitrary files from the server filesystem. The vulnerability requires authentication but poses significant risk due to potential exposure of sensitive internal resources and cloud infrastructure metadata. A pull request has been submitted to address the issue, and a proof-of-concept advisory has been published on GitHub.

Technical details

Mitigation steps:

Affected products:

Leantime 3.6.2

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page