Template Traversal Vulnerability in Horilla HR and CRM Software
CVE-2026-63432
What is CVE-2026-63432?
Horilla HR and CRM software versions from 1.0.0 to 1.6.0 and 2.0.0 are susceptible to a template traversal vulnerability. This issue arises when handlers in the recruitment and employee modules render user-controlled inputs into the Django template context. Authenticated users, armed with valid CSRF tokens, can exploit this to traverse template attributes and gain access to sensitive information such as user passwords, personal data, and server metadata. Though not allowing arbitrary code execution, this flaw poses a risk of data exposure and could enable offline password cracking attacks. The vulnerability has been addressed in versions 1.6.0 and 2.0.0.
Affected Version(s)
horilla-hr >= 1.0.0, < 1.6.0 < 1.0.0, 1.6.0
horilla-hr >= 2.0.0-beta.1, < 2.0.0 < 2.0.0-beta.1, 2.0.0
