Junglewise Threat Intelligence

Kimai API token hash leak in invoice Twig templates

Severity: low · CVSS 2 · Published 2026-04-14

Technologies: kimai/kimai (Packagist), Kimai. Vendors: Packagist, Kimai.

Executive brief

Kimai is an open-source time-tracking application. A vulnerability in its invoice template system allows administrators to create malicious templates that leak sensitive security tokens of other users. When a user generates an invoice using a compromised template, their hashed API credentials may be exposed in the final document, potentially allowing an attacker to attempt to crack the credentials and gain unauthorized API access.

Technical details

The vulnerability exists in the Twig sandbox environment used for rendering invoice templates. While Kimai's 'StrictPolicy' class implements a blocklist to prevent access to sensitive User object methods (like passwords and TOTP secrets), it failed to include 'getApiToken()' and 'getPlainApiToken()'. An attacker with 'manage_invoice_template' permissions can create a template that calls these methods. When a victim generates an invoice using this template, their bcrypt or sodium hashed API password is leaked into the rendered output. This affects On-Premise installations where template uploads are enabled; the cloud version is not affected as it restricts template uploads. The issue is addressed in version 2.53.0 by implementing a more robust keyword-based exclusion policy.

Affected products

  • Kimai Kimai <= 2.52.0

Timeline

  • 2026-04-11: disclosed: Initial disclosure by researcher Het Patel
  • 2026-04-14: advisory: GitHub Advisory published
  • 2026-04-14: patched: Fix released in version 2.53.0

References

Related threats