Impact
Leantime prior to version 3.9.6 contains an authorization bypass in the HTMX plugin install endpoint. The endpoint accepts metadata such as plugin identifier, version, and license key without validating the caller’s role. A logged‑in user with a limited role can therefore register and activate arbitrary marketplace plugins, effectively installing code of the attacker’s choosing and achieving full control of the application instance.
Affected Systems
Any deployment of Leantime older than 3.9.6 is affected. The vulnerability resides in the Leantime application and is identified under the vendor product Leantime:Leantime. Users must verify that they are running version 3.9.6 or newer to avoid exposure.
Risk and Exploitability
The CVSS score of 7.1 places this issue in the high severity range. The EPSS score is below 1%, indicating low current exploitation probability, and the vulnerability is not listed in CISA KEV. The attack requires an authenticated user with a non‑admin role to send a crafted request to the HTMX plugin install endpoint. Successful exploitation leads to arbitrary code execution under the application’s privileges. The risk is internal, stemming from insufficient permission checks, and can result in complete compromise of the affected instance.
OpenCVE Enrichment