Server-Side Request Forgery Vulnerability in InvoiceShelf by InvoiceShelf
CVE-2026-34367
7.6HIGH
What is CVE-2026-34367?
The InvoiceShelf application, which helps users manage expenses and generate invoices, contains a Server-Side Request Forgery (SSRF) vulnerability in its PDF generation module. This security flaw allows attacker-supplied HTML in the invoice Notes field to be processed without proper sanitization, leading the Dompdf rendering library to fetch remote resources. This issue can be exploited through the PDF preview and email delivery functionalities, compromising system security. Users are advised to update to version 2.2.0, where this vulnerability has been addressed.
Affected Version(s)
InvoiceShelf < 2.2.0
