Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 26 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can embed these method calls in invoice templates to leak hashed API tokens in rendered invoice output. | |
| Title | Kimai before 2.53.0 API Token Leakage via Invoice Template | |
| First Time appeared |
Kimai
Kimai kimai |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:kimai:kimai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kimai
Kimai kimai |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-26T14:16:34.776Z
Reserved: 2026-08-25T23:14:37.730Z
Link: CVE-2026-80201
Updated: 2026-08-26T14:16:30.327Z
Status : Received
Published: 2026-08-26T05:18:27.830
Modified: 2026-08-26T15:17:05.050
Link: CVE-2026-80201
No data.
OpenCVE Enrichment
Updated: 2026-08-26T01:30:16Z
-
CWE-94
Improper Control of Generation of Code ('Code Injection')