Executive brief
Kimai, an open-source time-tracking application, is vulnerable to a security flaw in its invoice generation system. An attacker with the ability to edit customer or invoice text can embed malicious links that force the server to make unauthorized requests to internal or external networks. This could allow an attacker to probe your internal network for other vulnerable systems or sensitive data that is not normally accessible from the internet.
Technical details
A Server-Side Request Forgery (SSRF) exists in Kimai's invoice rendering pipeline. When user-controlled Markdown (such as Customer.invoiceText) is processed, the md2html filter converts Markdown image syntax into HTML. The resulting HTML is then processed by the mPDF library, which attempts to fetch the remote image resources from the server side. An attacker with low privileges can exploit this to perform internal network scanning or reachability checks. The vulnerability is patched in version 2.58.0 by disabling Markdown images in favor of HTML links and implementing a specialized HttpClient (NoPrivateNetworkHttpClient) that restricts access to private network ranges.
Affected products
- Kimai Kimai <= 2.57.0
Timeline
- 2026-06-03: disclosed: Initial disclosure to vendor
- 2026-07-10: advisory: GitHub Advisory published
- 2026-07-10: patched: Fix released in version 2.58.0