← back
CVE-2026-80201lowCWE-94

Kimai before 2.53.0 API Token Leakage via Invoice Template

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 2epss 0.3%
exploitation probability
0.3%top 85% of all CVEs
observed exploitation
nono source reports it
Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can embed these method calls in invoice templates to leak hashed API tokens in rendered invoice output.
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
kimai · kimai