A critical configuration injection vulnerability exists in the application’s setup module.
The db_hostname parameter is not properly sanitized during installation, allowing attackers
to inject arbitrary configuration values. This can lead to environment manipulation, debug
mode activation, and potential remote code execution depending on deployment context.
InvoicePlane 1.7.1 - RCE
October 04, 2026 at 16:12
#1