


Perceptive Security
SOC/SIEM Consultancy

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a Se…
Published:
30 maart 2026 om 22:00:00
Alert date:
31 maart 2026 om 21:01:33
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
InvoiceShelf, an open-source web and mobile application for tracking expenses and creating invoices, contains a Server-Side Request Forgery (SSRF) vulnerability in versions prior to 2.2.0. The vulnerability exists in the Estimate PDF generation module where user-supplied HTML in the estimate Notes field is passed unsanitized to the Dompdf rendering library. This allows attackers to make the server fetch remote resources referenced in the markup. The vulnerability can be exploited through PDF preview and customer view endpoints regardless of email attachment settings. The issue has been patched in version 2.2.0.
Technical details
Mitigation steps:
Affected products:
InvoiceShelf
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-34365
https://github.com/InvoiceShelf/InvoiceShelf/releases/tag/2.2.0
https://github.com/InvoiceShelf/InvoiceShelf/security/advisories/GHSA-pc5v-8xwc-v9xq
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
