Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Jul 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Leantime
Leantime leantime |
|
| Vendors & Products |
Leantime
Leantime leantime |
Thu, 30 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path validation. Attackers can submit crafted filenames containing URL wrappers or path traversal sequences through the JSON-RPC API endpoint to access cloud metadata services or read arbitrary files from the server filesystem. | |
| Title | Leantime Server-Side Request Forgery and Local File Inclusion in Blueprints::import() | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-30T17:31:57.578Z
Reserved: 2026-07-27T05:16:45.792Z
Link: CVE-2026-66415
Updated: 2026-07-30T17:31:54.467Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T18:30:04Z
-
CWE-918
Server-Side Request Forgery (SSRF)