Junglewise Threat Intelligence

CVE-2026-34367: InvoiceShelf SSRF in Invoice PDF generation module

CVE-2026-34367 · Severity: high · CVSS 7.6 · Published 2026-03-31

Technologies: Invoiceshelf. Vendors: Invoiceshelf.

Executive brief

InvoiceShelf is an open-source application used for managing business expenses and generating professional invoices. A security flaw in the invoice generation system allows users with high-level permissions to force the server to make unauthorized requests to internal or external websites. This could lead to the exposure of sensitive internal data, access to cloud service credentials, or unauthorized scanning of the company's private network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in InvoiceShelf's PDF generation module due to insufficient sanitization of the 'Notes' field. When an invoice is rendered as a PDF via the Dompdf library, unsanitized HTML tags (such as <img> or <link>) are processed, causing the server to fetch remote resources. An attacker with high privileges can exploit this via the PDF preview or email delivery endpoints to perform internal network reconnaissance, access cloud metadata services (e.g., AWS/GCP), or potentially read local files. If Dompdf's 'isPhpEnabled' setting is active, this could also lead to remote code execution. The issue is resolved in version 2.2.0 by implementing HTML sanitization for the Notes field.

Affected products

  • InvoiceShelf InvoiceShelf < 2.2.0

Timeline

  • 2026-03-24: patched: Version 2.2.0 released
  • 2026-03-27: advisory: GitHub Security Advisory published
  • 2026-03-31: disclosed: CVE-2026-34367 published to NVD

References

Related threats