Junglewise Threat Intelligence

CVE-2026-14791: Crater stored XSS in Invoice Note Handler

CVE-2026-14791 · Severity: low · CVSS 3.5 · Published 2026-07-06

Executive brief

Crater, an open-source invoicing platform, contains a security flaw that allows users with invoice-creation privileges to inject malicious scripts into invoice notes. When a customer views their invoice through the online portal, this script can execute in their browser, potentially allowing an attacker to steal session tokens, perform credential phishing, or redirect the user to malicious websites. This risk is particularly high because it affects both the web-based customer portal and generated PDF documents.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Crater up to version 6.0.6 due to improper sanitization of the 'notes' field in the Invoice Note Handler. The vulnerability originates in 'app/Http/Requests/InvoicesRequest.php', where input is not validated, and 'app/Traits/GeneratesPdfTrait.php', where the 'getFormattedString()' function fails to strip dangerous HTML tags. The malicious payload is subsequently rendered unescaped in the customer portal via Vue's 'v-html' directive in 'InvoiceInformationCard.vue' and in PDF templates using Laravel's '{!! !!}' unescaped output directive. An authenticated attacker with 'create-invoice' or 'edit-invoice' permissions can execute arbitrary JavaScript in the context of a customer's browser session. As of the advisory date, no official patch has been released.

Affected products

  • crater-invoice-inc Crater up to 6.0.6

Timeline

  • 2026-05-15: other: Vulnerability confirmed on HEAD version
  • 2026-06-06: disclosed: Public issue report opened on GitHub
  • 2026-07-06: advisory: CVE published to NVD

References