CVE-2026-39362High· 7.1▾ TwilightInvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is enabled (opt-in), authenticated users can supply remote_image URLs that are fetched server-side via requests.get() wit…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is enabled (opt-in), authenticated users can supply remote_image URLs that are fetched server-side via requests.get() with only Django's URLValidator check. There is no validation against private IP ranges or internal hostnames. Redirects are followed (allow_redirects=True), enabling bypass of any URL-format checks. This vulnerability is fixed in 1.2.7 and 1.3.0.
inventree < 1.2.7Upgrade past the affected range:
inventree 1.2.7Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61749Medium· 6.5InvenTree is an Open Source Inventory Management System
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents
CVE-2026-35479Medium· 6.6InvenTree is an Open Source Inventory Management System
CVE-2026-35476High· 7.2InvenTree is an Open Source Inventory Management System
CVE-2026-35477Medium· 5.5InvenTree is an Open Source Inventory Management System
CVE-2026-35478High· 8.3InvenTree is an Open Source Inventory Management System