CVE-2026-33531Medium· 6.5▾ TwilightPoC availableInvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report template engine allows a staff-level user to read arbitrary files from the server filesystem via crafted templa…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
1 GitHub repo (last check)
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report template engine allows a staff-level user to read arbitrary files from the server filesystem via crafted template tags. Affected functions: encode_svg_image(), asset(), and uploaded_image() in src/backend/InvenTree/report/templatetags/report.py. This requires staff access (to upload / edit templates with maliciously crafted tags). If the InvenTree installation is configured with high access privileges on the host system, this path traversal may allow file access outside of the InvenTree source directory. This issue is patched in version 1.2.6, and 1.3.0 (or above). Users should update to the patched versions. No known workarounds are available.
inventree < 1.2.6Upgrade past the affected range:
inventree 1.2.6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61746Medium· 5.3InvenTree is an Open Source Inventory Management System
CVE-2026-61745Medium· 4.3InvenTree is an Open Source Inventory Management System
CVE-2026-33530High· 7.7InvenTree is an Open Source Inventory Management System
CVE-2026-35479Medium· 6.6InvenTree is an Open Source Inventory Management System
CVE-2026-39362High· 7.1InvenTree is an Open Source Inventory Management System
CVE-2026-35476High· 7.2InvenTree is an Open Source Inventory Management System