Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can embed these method calls in invoice templates to leak hashed API tokens in rendered invoice output.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can embed these method calls in invoice templates to leak hashed API tokens in rendered invoice output. | |
| Title | Kimai before 2.53.0 API Token Leakage via Invoice Template | |
| First Time appeared |
Kimai
Kimai kimai |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:kimai:kimai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kimai
Kimai kimai |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T23:19:06.486Z
Reserved: 2026-08-25T23:14:37.730Z
Link: CVE-2026-80201
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-26T01:30:16Z