Description
Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is later rendered into an invoice PDF, such as `Customer.invoiceText`, the server-side PDF renderer will fetch remote image URLs embedded in Markdown image syntax. This allows the application server to issue outbound requests to attacker-controlled or internal targets during PDF rendering. The behavior can be used for internal network probing, server-side reachability checks, and potentially follow-on exploitation depending on deployment environment and accessible internal services. Version 2.58.0 patches the issue.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Immediate Patch
AI Analysis

Impact

Kimai is an open‑source time‑tracking application. Versions prior to 2.58.0 contain a server‑side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is later rendered into an invoice PDF, such as `Customer.invoiceText`, the server‑side PDF renderer will fetch remote image URLs embedded in Markdown image syntax. This allows the application server to issue outbound requests to attacker‑controlled or internal targets during PDF rendering. The behavior can be used for internal network probing, server‑side reachability checks, and potentially follow‑on exploitation depending on deployment environment and accessible internal services. Version 2.58.0 patches the issue.

Affected Systems

Versions of Kimai earlier than 2.58.0 are affected. The vulnerability resides in the PDF rendering workflow that processes Markdown images. No specific CPE stratification is listed; the vendor product is Kimai by Kimai.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity. The EPSS score is < 1%, indicating a low probability of exploitation. The issue is not listed in the CISA KEV catalog. An attacker must have the ability to inject or otherwise influence the Markdown content used in invoices. Upon rendering, the server will send outbound HTTP(S) requests to the URLs specified in the Markdown image syntax, potentially revealing internal endpoints or providing access to internal services that are otherwise unreachable from the public Internet. The impact is limited to servers that process untrusted Markdown content for invoices.

Generated by OpenCVE AI on September 15, 2026 at 19:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kimai to version 2.58.0 or later, which removes the SSRF flaw in PDF rendering.
  • If an upgrade cannot be performed immediately, disable or strip Markdown image syntax from invoice PDFs to prevent external URL fetching.
  • Restrict outbound network traffic from the Kimai application server with a firewall or proxy so that only authorized destinations can be contacted, thereby mitigating the effect of any remaining SSRF capability.

Generated by OpenCVE AI on September 15, 2026 at 19:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pj8j-p4g4-4vw8 Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Kimai
Kimai kimai
Vendors & Products Kimai
Kimai kimai

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is later rendered into an invoice PDF, such as `Customer.invoiceText`, the server-side PDF renderer will fetch remote image URLs embedded in Markdown image syntax. This allows the application server to issue outbound requests to attacker-controlled or internal targets during PDF rendering. The behavior can be used for internal network probing, server-side reachability checks, and potentially follow-on exploitation depending on deployment environment and accessible internal services. Version 2.58.0 patches the issue.
Title Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T19:58:41.023Z

Reserved: 2026-06-01T22:03:19.641Z

Link: CVE-2026-49865

cve-icon Vulnrichment

Updated: 2026-09-14T19:58:38.159Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T21:17:10.783

Modified: 2026-09-23T18:22:16.503

Link: CVE-2026-49865

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:45:07Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)