# CVE-2026-25548

## Summary

- **CVE ID:** CVE-2026-25548
- **Severity:** CRITICAL
- **CVSS Score:** 9.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-94, CWE-98, CWE-117
- **Published:** Feb 18, 2026
- **Last Modified:** Mar 12, 2026

## Description

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerability exists in InvoicePlane 1.7.0 through a chained Local File Inclusion (LFI) and Log Poisoning attack. An authenticated administrator can execute arbitrary system commands on the server by manipulating the `public_invoice_template` setting to include poisoned log files containing PHP code. Version 1.7.1 patches the issue.

## Affected Products

- InvoicePlane — InvoicePlane (<= 1.7.0)

## References

- [CNA](https://github.com/InvoicePlane/InvoicePlane/security/advisories/GHSA-g6rw-m9mf-33ch)
- [CNA](https://github.com/InvoicePlane/InvoicePlane/commit/93622f2df88a860d89bfee56012cabb2942061d6)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.77%
- **EPSS Percentile:** 53.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._