Arbitrary Code Execution Vulnerability in SolidInvoice Open-Source Invoicing Platform
CVE-2026-61686
7.5HIGH
What is CVE-2026-61686?
In the SolidInvoice open-source invoicing platform, prior to version 3.0.1, a vulnerability exists in the DataGrid LiveComponent. This issue arises from the insecure deserialization of a client-supplied context prop using PHP's unserialize() method. The context prop, marked writable: true, allows an authenticated attacker to inject a maliciously constructed PHP serialized payload, potentially resulting in arbitrary code execution. The vulnerability has been addressed in version 3.0.1.
Affected Version(s)
SolidInvoice < 3.0.1
