CVE-2026-49865Medium· 5.3▾ TwilightPoC availableKimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is lat…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.2 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
5.3 → —
— → 5.3
5.3 → —
— → 5.3
5.3 → —
— → 5.3
5.3 → —
— → 5.3
5.3 → —
— → 5.3
5.3 → —
— → 5.3
1 GitHub repo (last check)
Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is later rendered into an invoice PDF, such as Customer.invoiceText, the server-side PDF renderer will fetch remote image URLs embedded in Markdown image syntax. This allows the application server to issue outbound requests to attacker-controlled or internal targets during PDF rendering. The behavior can be used for internal network probing, server-side reachability checks, and potentially follow-on exploitation depending on deployment environment and accessible internal services. Version 2.58.0 patches the issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
kimai/kimai <= 2.57.0Patched in:
kimai/kimai 2.58.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-52819Medium· 6.3Kimai is an open-source time tracking application
CVE-2026-52824Critical· 9.1Kimai is an open-source time tracking application
CVE-2026-52827High· 7.1Kimai is an open-source time tracking application
CVE-2026-52828Medium· 5.3Kimai is an open-source time tracking application
CVE-2026-49992Medium· 6.3Kimai is an open-source time tracking application
CVE-2026-52820Medium· 5.3Kimai is an open-source time tracking application