API Token Exposure in Kimai Due to Invoice Template Vulnerabilities
CVE-2026-80201
2LOW
What is CVE-2026-80201?
Kimai versions prior to 2.53.0 are susceptible to a vulnerability that allows attackers with template creation permissions to call sensitive user methods in the Twig invoice template sandbox. This oversight presents the potential for malicious actors to embed method calls within invoice templates, leading to the unintentional disclosure of hashed API tokens in the rendered output of invoices. Proper security measures and timely updates are essential to mitigate this risk and protect sensitive information.
Affected Version(s)
kimai 0 < 2.53.0
kimai 2.53.0
