Impact
Kimai is an open‑source time‑tracking application. Versions prior to 2.58.0 contain a server‑side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is later rendered into an invoice PDF, such as `Customer.invoiceText`, the server‑side PDF renderer will fetch remote image URLs embedded in Markdown image syntax. This allows the application server to issue outbound requests to attacker‑controlled or internal targets during PDF rendering. The behavior can be used for internal network probing, server‑side reachability checks, and potentially follow‑on exploitation depending on deployment environment and accessible internal services. Version 2.58.0 patches the issue.
Affected Systems
Versions of Kimai earlier than 2.58.0 are affected. The vulnerability resides in the PDF rendering workflow that processes Markdown images. No specific CPE stratification is listed; the vendor product is Kimai by Kimai.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. The EPSS score is < 1%, indicating a low probability of exploitation. The issue is not listed in the CISA KEV catalog. An attacker must have the ability to inject or otherwise influence the Markdown content used in invoices. Upon rendering, the server will send outbound HTTP(S) requests to the URLs specified in the Markdown image syntax, potentially revealing internal endpoints or providing access to internal services that are otherwise unreachable from the public Internet. The impact is limited to servers that process untrusted Markdown content for invoices.
OpenCVE Enrichment
Github GHSA