CVE-2026-61749 | InvenTree up to 1.3.x Report Rendering write_pdf html server-side request forgery

SecurityVulns

A vulnerability, which was classified as problematic, was found in InvenTree up to 1.3.x. This issue affects the function write_pdf of the component Report Rendering. Executing a manipulation of the argument html can lead to server-side request forgery.

The identification of this vulnerability is CVE-2026-61749. The attack may be launched remotely. There is no exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More