Server-Side Request Forgery and Local File Inclusion in Leantime by Leantime
CVE-2026-66415

8.4HIGH

Key Information:

Vendor

Leantime

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-66415?

Leantime 3.6.2 is affected by a server-side request forgery (SSRF) and local file inclusion (LFI) vulnerability. This issue arises when the application inadequately validates user-supplied filenames in the Blueprints::import() method. Authenticated attackers can exploit this flaw by sending carefully crafted filenames through the JSON-RPC API endpoint, potentially gaining unauthorized access to sensitive internal resources. The vulnerability facilitates access to cloud metadata services and allows attackers to read arbitrary files from the server filesystem, which poses significant risks to data integrity and confidentiality.

Affected Version(s)

Leantime 0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Javokhir Tursunboyev (@javokhir-sec)
.