CVE-2026-80201

Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can embed these method calls in invoice templates to leak hashed API tokens in rendered invoice output.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-26 05:18

Updated : 2026-08-31 20:52


NVD link : CVE-2026-80201

Mitre link : CVE-2026-80201

CVE.ORG link : CVE-2026-80201


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')