Skip to content
Threat Feed
high advisory

Remote Code Execution in InvoicePlane via Configuration Injection

InvoicePlane 1.7.1 is vulnerable to remote code execution (CVE-2026-40297) due to unsanitized input in the setup module, allowing attackers to inject arbitrary configuration directives.

InvoicePlane version 1.7.1 contains a critical configuration injection vulnerability (CVE-2026-40297) located within the application's setup module. The vulnerability stems from improper input validation of the 'db_hostname' parameter during the initial installation flow. An unauthenticated attacker can supply malicious input to this parameter to inject arbitrary configuration values into the application's runtime environment. This can be leveraged to activate debug modes, manipulate environment variables, and ultimately achieve remote code execution depending on the server deployment context. This vulnerability was disclosed alongside a proof-of-concept that demonstrates the sequential exploitation of CSRF-protected steps to facilitate the configuration injection.

Attack Chain

  1. Attacker initiates the InvoicePlane setup process by accessing the /index.php/setup/language endpoint.
  2. Attacker scrapes the first CSRF token (_ip_csrf) from the language selection page.
  3. Attacker submits the language step via POST to confirm the configuration flow progress.
  4. Attacker navigates to the /index.php/setup/prerequisites endpoint to retrieve the secondary CSRF token.
  5. Attacker submits the prerequisites step via POST to advance the installer.
  6. Attacker navigates to the /index.php/setup/configure_database endpoint and retrieves the final CSRF token.
  7. Attacker submits a POST request to configure_database containing a crafted db_hostname payload that escapes the expected string and injects new configuration lines (e.g., ENABLE_DEBUG=true).
  8. Application parses the injected configuration, resulting in environment manipulation and potential remote code execution.

Impact

Successful exploitation allows an attacker to inject arbitrary configuration, modify application behavior, and potentially execute code with the permissions of the web server user. This vulnerability exposes the application to full compromise during the setup phase, affecting any deployment running version 1.7.1.

Recommendation

Prioritized actions for security teams:

  • Patch immediately by upgrading InvoicePlane to version 1.7.2 or later.
  • Implement strict network access controls to the /setup/ directory to prevent unauthenticated access to the installation module.
  • Audit web application access logs for repeated POST requests to '/index.php/setup/configure_database' originating from unauthorized IP addresses.
  • Deploy web application firewall (WAF) rules to detect and block requests to '/index.php/setup/configure_database' containing injected configuration directives (e.g., ENABLE_DEBUG, newline characters followed by configuration keys) within the 'db_hostname' parameter.

Immediate actions

Upgrade InvoicePlane to 1.7.2 or later.

IT Operations 24h

Threat Hunt

Unauthorized POST requests to setup configuration endpoint.

T1190 high high confidence hunt now

Data: Web server access logs

Mitigations

Restrict access to /setup/ directory via WAF or web server configuration.

immediate IT Operations

CVE-2026-40297

Detection coverage 1

Detect CVE-2026-40297 Exploitation - Configuration Injection in InvoicePlane

high

Detects exploitation attempts against CVE-2026-40297 by identifying malicious newline character injection in the db_hostname parameter during the setup database configuration step.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →