LOW
Kimai before 2.53.0 API Token Leakage via Invoice Template
Published Aug 25, 2026
2.0
LOWCVSS 4.0
EPSS 0.26%
Description
Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can embed these method calls in invoice templates to leak hashed API tokens in rendered invoice output.
Affected products
-
- Version 0StatusaffectedConstraints<2.53.0
- Version 2.53.0StatusunaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://github.com/kimai/kimai/security/advisories/GHSA-rh42-6rj2-xwmc exploitvendor-advisory
- https://www.vulncheck.com/advisories/kimai-before-2.53.0-api-token-leakage-via-invoice-template third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/kimai/kimai/security/advisories/GHSA-rh42-6rj2-xwmc | exploitvendor-advisory | |
| https://www.vulncheck.com/advisories/kimai-before-2.53.0-api-token-leakage-via-invoice-template | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 25, 2026
Updated Aug 26, 2026
Reserved Aug 25, 2026
Link CVE-2026-80201
CISA Vulnrichment
Updated Aug 26, 2026