---
id: CVE-2022-3355
aliases:
  - GHSA-62g7-fpv9-v95f
  - PYSEC-2026-823
title: Inventree vulnerable to Stored Cross-site Scripting
summary: Inventree vulnerable to Stored Cross-site Scripting
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
vendor: inventree
product: inventree
ecosystem: pip
affected:
  - inventree < 0.8.3
patched:
  - inventree 0.8.3
published: '2022-09-30'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-62g7-fpv9-v95f'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-3355'
  - url: >-
      https://github.com/inventree/inventree/commit/5a08ef908dd5344b4433436a4679d122f7f99e41
  - url: 'https://github.com/inventree/InvenTree/releases/tag/0.8.3'
  - url: 'https://github.com/inventree/inventree'
  - url: 'https://huntr.dev/bounties/4b7fb92c-f06b-4bbf-82dc-9f013b30b6a6'
tags:
  - osv
  - pip
epss: 0.00684
epssPercentile: 0.51157
ingestedAt: '2026-07-08T18:25:46.259Z'
---

## Overview

Inventree prior to 0.8.3 is vulnerable to stored cross-site scripting by uploading SVG files. Version 0.8.3 contains a patch for this issue.

## Affected packages

- `inventree < 0.8.3`

## Remediation

Upgrade to a patched release:

- `inventree 0.8.3`
