Server-Side Request Forgery Vulnerability in InvoiceShelf Web and Mobile Application
CVE-2026-34365

7.6HIGH

Key Information:

Vendor
CVE Published:
31 March 2026

What is CVE-2026-34365?

InvoiceShelf, an open-source web and mobile application designed for expense tracking and invoice generation, contains a Server-Side Request Forgery vulnerability in its Estimate PDF generation module. This flaw arises because user-provided HTML in the estimate Notes field is transmitted without sanitation to the Dompdf rendering library. Consequently, this enables the potential fetching of remote resources indicated in the markup. The vulnerability is accessible directly via the PDF preview and customer view endpoints, regardless of the status of automated email attachments. The issue has been rectified in version 2.2.0 of the software.

Affected Version(s)

InvoiceShelf < 2.2.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.