Path Traversal Vulnerability in InvoicePlane by InvoicePlane
CVE-2026-23491
9.3CRITICAL
What is CVE-2026-23491?
A path traversal vulnerability exists in the get_file method of the Guest module's Get controller in InvoicePlane versions up to 1.6.3. This issue allows unauthenticated attackers to manipulate input filenames and gain access to arbitrary files on the server. Consequently, this can lead to the exposure of sensitive information, such as configuration files containing database credentials. This vulnerability has been addressed in version 1.6.4.
Affected Version(s)
InvoicePlane < 1.6.4
