CRLF Injection Vulnerability in InvoicePlane by InvoicePlane
CVE-2026-85290

5.3MEDIUM

Key Information:

Vendor
CVE Published:
25 September 2026

What is CVE-2026-85290?

InvoicePlane, a self-hosted open source application for managing invoices, clients, and payments, suffers from a CRLF injection vulnerability in its Cron::recur() method. Prior to version 1.7.2, the application improperly handles user input by directly writing an invalid cron key from the URL path to the application log without neutralizing CRLF characters. This flaw allows an unauthenticated attacker to inject crafted log entries, potentially corrupting the audit trail and affecting log-based monitoring systems. The vulnerability has been addressed and fixed in version 1.7.2.

Affected Version(s)

InvoicePlane < 1.7.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.