Template Traversal Vulnerability in Horilla HR and CRM Software
CVE-2026-63432

6.5MEDIUM

Key Information:

Vendor

Horilla

Vendor
CVE Published:
25 September 2026

What is CVE-2026-63432?

Horilla HR and CRM software versions from 1.0.0 to 1.6.0 and 2.0.0 are susceptible to a template traversal vulnerability. This issue arises when handlers in the recruitment and employee modules render user-controlled inputs into the Django template context. Authenticated users, armed with valid CSRF tokens, can exploit this to traverse template attributes and gain access to sensitive information such as user passwords, personal data, and server metadata. Though not allowing arbitrary code execution, this flaw poses a risk of data exposure and could enable offline password cracking attacks. The vulnerability has been addressed in versions 1.6.0 and 2.0.0.

Affected Version(s)

horilla-hr >= 1.0.0, < 1.6.0 < 1.0.0, 1.6.0

horilla-hr >= 2.0.0-beta.1, < 2.0.0 < 2.0.0-beta.1, 2.0.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.