LOW 2.0 NVD
CVE-2026-80201
Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() met
Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can embed these method calls in invoice templates to leak hashed API tokens in rendered invoice output.
References
- https://github.com/kimai/kimai/security/advisories/GHSA-rh42-6rj2-xwmc
- https://www.vulncheck.com/advisories/kimai-before-2.53.0-api-token-leakage-via-invoice-tem
- https://github.com/kimai/kimai/security/advisories/GHSA-rh42-6rj2-xwmc
This low severity vulnerability with a CVSS score of 2.0 was published on 2026-08-26 via NVD.
vulnfeed aggregates 11364 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.