Server-Side Request Forgery in InvoiceShelf Payment Receipt Module
CVE-2026-34366

7.6HIGH

Key Information:

Vendor
CVE Published:
31 March 2026

What is CVE-2026-34366?

InvoiceShelf, an open-source web and mobile application designed for tracking expenses and generating professional invoices, had a Server-Side Request Forgery (SSRF) vulnerability affecting its payment receipt PDF generation module prior to version 2.2.0. In this version, user-supplied HTML in the payment notes field was passed to the Dompdf rendering library without proper sanitization, allowing it to fetch remote resources specified in the markup. This vulnerability could be exploited directly through the PDF receipt endpoint, even if automated email attachments were disabled. The issue has been addressed in version 2.2.0.

Affected Version(s)

InvoiceShelf < 2.2.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.