Server-Side Request Forgery and Local File Inclusion in Leantime by Leantime
CVE-2026-66415
8.4HIGH
What is CVE-2026-66415?
Leantime 3.6.2 is affected by a server-side request forgery (SSRF) and local file inclusion (LFI) vulnerability. This issue arises when the application inadequately validates user-supplied filenames in the Blueprints::import() method. Authenticated attackers can exploit this flaw by sending carefully crafted filenames through the JSON-RPC API endpoint, potentially gaining unauthorized access to sensitive internal resources. The vulnerability facilitates access to cloud metadata services and allows attackers to read arbitrary files from the server filesystem, which poses significant risks to data integrity and confidentiality.
Affected Version(s)
Leantime 0
