InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report template engine allows a staff-level user to read arbitrary files from the server filesystem via crafted template tags. Affected functions: encode_svg_image(), asset(), and uploaded_image() in src/backend/InvenTree/report/templatetags/report.py. This requires staff access (to upload / edit templates with maliciously crafted tags). If the InvenTree installation is configured with high access privileges on the host system, this path traversal may allow file access outside of the InvenTree source directory. This issue is patched in version 1.2.6, and 1.3.0 (or above). Users should update to the patched versions. No known workarounds are available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a documentation-heavy proof-of-concept for CVE-2026-33531, a path traversal vulnerability in InvenTree report templates. It is not a standalone exploit tool or framework module; instead it contains explanatory material, a demo template, attack-flow notes, and excerpts of the vulnerable logic. The core issue is that three Django template tags in InvenTree's report engine—encode_svg_image(), asset(), and uploaded_image()—resolve user-supplied filenames with Path.resolve() but, in vulnerable versions, do not verify that the resolved path remains under MEDIA_ROOT. A staff user can therefore create or edit a report template containing traversal sequences, and when any authenticated user triggers report generation, the server reads local files and embeds their contents into the resulting PDF or loads them through a file:// URI via WeasyPrint. Repository structure: README.md summarizes the CVE, affected versions, and references; Poc/demo_template.txt contains safe examples plus a descriptive traversal example; Poc/notes.md explains prerequisites and conceptual reproduction; Technical-Analysis/Attack-Flow.md provides a Mermaid attack diagram; Technical-Analysis/vulnerable_functions.md is the most actionable file, documenting the vulnerable functions, showing example curl requests to create a malicious template and trigger printing, and describing PDF-based exfiltration. References/links.md aggregates advisory, source, and vulnerability-class links. Main exploit capability: arbitrary file read from the server filesystem, bounded by the privileges of the InvenTree application process and requiring staff access to template editing. The exploit path is web/network-based through InvenTree API endpoints for template upload and report printing. The repository includes concrete example endpoints (/api/report/template/, /api/report/print/, and a sample PDF download path), but it remains a POC/documentation set rather than a weaponized exploit. The documented fix is to upgrade to InvenTree 1.2.6 or 1.3.0+, where Path.is_relative_to(MEDIA_ROOT) checks were added after resolve().
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.