Back

LOW

Kimai before 2.53.0 API Token Leakage via Invoice Template

Published Aug 25, 2026

Description

Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can embed these method calls in invoice templates to leak hashed API tokens in rendered invoice output.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 25, 2026
Updated Aug 26, 2026
Reserved Aug 25, 2026
CISA Vulnrichment
Updated Aug 26, 2026
NVD
Status Deferred
Modified Aug 31, 2026
Red Hat
Severity n/a
Public date n/a