Server-Side Request Forgery Vulnerability in InvoiceShelf Web and Mobile Application
CVE-2026-34365
7.6HIGH
What is CVE-2026-34365?
InvoiceShelf, an open-source web and mobile application designed for expense tracking and invoice generation, contains a Server-Side Request Forgery vulnerability in its Estimate PDF generation module. This flaw arises because user-provided HTML in the estimate Notes field is transmitted without sanitation to the Dompdf rendering library. Consequently, this enables the potential fetching of remote resources indicated in the markup. The vulnerability is accessible directly via the PDF preview and customer view endpoints, regardless of the status of automated email attachments. The issue has been rectified in version 2.2.0 of the software.
Affected Version(s)
InvoiceShelf < 2.2.0
