Server-Side Request Forgery in InvoiceShelf Payment Receipt Module
CVE-2026-34366
7.6HIGH
What is CVE-2026-34366?
InvoiceShelf, an open-source web and mobile application designed for tracking expenses and generating professional invoices, had a Server-Side Request Forgery (SSRF) vulnerability affecting its payment receipt PDF generation module prior to version 2.2.0. In this version, user-supplied HTML in the payment notes field was passed to the Dompdf rendering library without proper sanitization, allowing it to fetch remote resources specified in the markup. This vulnerability could be exploited directly through the PDF receipt endpoint, even if automated email attachments were disabled. The issue has been addressed in version 2.2.0.
Affected Version(s)
InvoiceShelf < 2.2.0
