Executive brief
Kimai is a time-tracking and invoicing platform used by organizations to manage employee timesheets and generate billing documents. Administrators can upload custom templates for invoice and export generation. A vulnerability allows admin users to embed code in these templates that reads sensitive server configuration including LDAP passwords and SAML encryption keys, which are then exposed in invoices or reports that other employees download. This could lead to unauthorized access to company directory systems and forged authentication tokens.
Technical details
The Twig sandbox in Kimai's invoice and export template renderers allow-lists the config() function without filtering accessible keys. The config() function delegates to SystemConfiguration::find(), which returns arbitrary entries from the flattened kimai.config container parameter containing secrets such as ldap.connection.password and saml.connection.sp.privateKey. An authenticated attacker with admin privileges (ROLE_SUPER_ADMIN with upload_invoice_template permission) can craft a malicious template that renders these secrets into invoice PDFs, HTML exports, or CSV/XLSX files that are downloaded by lower-privileged users (teamleads, invoicing admins). The vulnerability requires admin account compromise or insider threat; the rendered output (invoices, exports) is then accessible to users with INVOICE permissions. The fix in version 2.56.0 restricts the config() function to a whitelist of safe theme-related keys only.
Affected products
- Kimai Kimai before 2.56.0
Timeline
- 2026-04-27: disclosed
- 2026-08-26: advisory
- 2026-04-27: patched: version 2.56.0