Unrated severityNVD Advisory· Published Aug 25, 2026
Kimai before 2.53.0 API Token Leakage via Invoice Template
CVE-2026-80201
Description
Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can embed these method calls in invoice templates to leak hashed API tokens in rendered invoice output.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/kimai/kimai/security/advisories/GHSA-rh42-6rj2-xwmcmitrevendor-advisory
- www.vulncheck.com/advisories/kimai-before-2.53.0-api-token-leakage-via-invoice-templatemitrethird-party-advisory
News mentions
0No linked articles in our index yet.