CVE-2026-27629
Last modified
CVE-2026-27629 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be hijacked to expose secure information to the client. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be hijacked to expose secure information to the client. When generating custom batch codes, the InvenTree server makes use of a customizable jinja2 template, which can be modified by a staff user to exfiltrate sensitive information or perform code execution on the server. This issue requires access by a user with granted staff permissions, followed by a request to generate a custom batch code via the API. Once the template has been modified in a malicious manner, the API call to generate a new batch code could be made by other users, and the template code will be executed with their user context. The code has been patched to ensure that all template generation is performed within a secure sandboxed context. This issue has been addressed in version 1.2.3, and any versions from 1.3.0 onwards. Some workarounds are available. The batch code template is a configurable global setting which can be adjusted via any user with staff access. To prevent this setting from being edited, it can be overridden at a system level to a default value, preventing it from being edited. This requires system administrator access, and cannot be changed from the client side once the server is running. It is recommended that for InvenTree installations prior to 1.2.3 the `STOCK_BATCH_CODE_TEMPLATE` and `PART_NAME_FORMAT` global settings are overridden at the system level to prevent editing.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Inventree Project | Inventree | < 1.2.3 |
References
- https://github.com/inventree/InvenTree/security/advisories/GHSA-cx85-vr3q-9x4mMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-27629?
How severe is CVE-2026-27629?
How do I fix CVE-2026-27629?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-27623Valkey is a distributed key-value database. Starting in vers…7.5
- CVE-2026-27624Coturn is a free open source implementation of TURN and STUN…6.5
- CVE-2026-27625Stirling-PDF is a locally hosted web application that perfor…6.5
- CVE-2026-27626OliveTin gives access to predefined shell commands from a we…9.9
- CVE-2026-27627Karakeep is a elf-hostable bookmark-everything app. In versi…6.1
- CVE-2026-27628pypdf is a free and open-source pure-python PDF library. Pri…7.5
- CVE-2026-2763Use-after-free in the JavaScript Engine component. This vuln…9.8
- CVE-2026-27630TinyWeb is a web server (HTTP, HTTPS) written in Delphi for …7.5
- CVE-2026-27631Exiv2 is a C++ library and a command-line utility to read, w…5.3
- CVE-2026-27632Talishar is a fan-made Flesh and Blood project. Prior to com…3.1
- CVE-2026-27633TinyWeb is a web server (HTTP, HTTPS) written in Delphi for …7.5
- CVE-2026-27634Piwigo is an open source photo gallery application for the w…9.8
Are you affected by CVE-2026-27629?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
