CRLF Injection Vulnerability in InvoicePlane by InvoicePlane
CVE-2026-85290
5.3MEDIUM
What is CVE-2026-85290?
InvoicePlane, a self-hosted open source application for managing invoices, clients, and payments, suffers from a CRLF injection vulnerability in its Cron::recur() method. Prior to version 1.7.2, the application improperly handles user input by directly writing an invalid cron key from the URL path to the application log without neutralizing CRLF characters. This flaw allows an unauthenticated attacker to inject crafted log entries, potentially corrupting the audit trail and affecting log-based monitoring systems. The vulnerability has been addressed and fixed in version 1.7.2.
Affected Version(s)
InvoicePlane < 1.7.2
