


Perceptive Security
SOC/SIEM Consultancy

Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by p…
Published:
30 juli 2026 om 00:00:00
Alert date:
30 juli 2026 om 22:07:35
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Zero-Day Vulnerabilities
Leantime version 3.6.2 contains a server-side request forgery (SSRF) and local file inclusion (LFI) vulnerability in the Blueprints::import() method. The flaw arises from passing unsanitized user-supplied filenames directly to PHP's file_get_contents() function without path validation. Authenticated attackers can exploit this via the JSON-RPC API endpoint by submitting crafted filenames containing URL wrappers or path traversal sequences. Successful exploitation allows attackers to access cloud metadata services or read arbitrary files from the server filesystem. The vulnerability requires authentication but poses significant risk due to potential exposure of sensitive internal resources and cloud infrastructure metadata. A pull request has been submitted to address the issue, and a proof-of-concept advisory has been published on GitHub.
Technical details
Mitigation steps:
Affected products:
Leantime 3.6.2
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-66415
https://github.com/Leantime/leantime
https://github.com/Leantime/leantime/pull/3656
https://github.com/javokhir-sec/CVE-PoC-Hub/security/advisories/GHSA-gphg-6h4g-mg22
https://www.vulncheck.com/advisories/leantime-server-side-request-forgery-and-local-file-inclusion-in-blueprints-import
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
