High severity7.5NVD Advisory· Published Sep 4, 2026· Updated Sep 4, 2026
CVE-2026-61686
CVE-2026-61686
Description
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the DataGrid LiveComponent deserializes a context prop value using PHP's unserialize() after receiving it from the client. Because the prop is marked writable: true, an authenticated attacker can supply an arbitrary PHP serialized payload. Version 3.0.1 fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.0.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.