Remote Code Execution in InvoicePlane via Configuration Injection
InvoicePlane 1.7.1 is vulnerable to remote code execution (CVE-2026-40297) due to unsanitized input in the setup module, allowing attackers to inject arbitrary configuration directives.
InvoicePlane version 1.7.1 contains a critical configuration injection vulnerability (CVE-2026-40297) located within the application's setup module. The vulnerability stems from improper input validation of the 'db_hostname' parameter during the initial installation flow. An unauthenticated attacker can supply malicious input to this parameter to inject arbitrary configuration values into the application's runtime environment. This can be leveraged to activate debug modes, manipulate environment variables, and ultimately achieve remote code execution depending on the server deployment context. This vulnerability was disclosed alongside a proof-of-concept that demonstrates the sequential exploitation of CSRF-protected steps to facilitate the configuration injection.
Attack Chain
- Attacker initiates the InvoicePlane setup process by accessing the /index.php/setup/language endpoint.
- Attacker scrapes the first CSRF token (_ip_csrf) from the language selection page.
- Attacker submits the language step via POST to confirm the configuration flow progress.
- Attacker navigates to the /index.php/setup/prerequisites endpoint to retrieve the secondary CSRF token.
- Attacker submits the prerequisites step via POST to advance the installer.
- Attacker navigates to the /index.php/setup/configure_database endpoint and retrieves the final CSRF token.
- Attacker submits a POST request to configure_database containing a crafted db_hostname payload that escapes the expected string and injects new configuration lines (e.g., ENABLE_DEBUG=true).
- Application parses the injected configuration, resulting in environment manipulation and potential remote code execution.
Impact
Successful exploitation allows an attacker to inject arbitrary configuration, modify application behavior, and potentially execute code with the permissions of the web server user. This vulnerability exposes the application to full compromise during the setup phase, affecting any deployment running version 1.7.1.
Recommendation
Prioritized actions for security teams:
- Patch immediately by upgrading InvoicePlane to version 1.7.2 or later.
- Implement strict network access controls to the /setup/ directory to prevent unauthenticated access to the installation module.
- Audit web application access logs for repeated POST requests to '/index.php/setup/configure_database' originating from unauthorized IP addresses.
- Deploy web application firewall (WAF) rules to detect and block requests to '/index.php/setup/configure_database' containing injected configuration directives (e.g., ENABLE_DEBUG, newline characters followed by configuration keys) within the 'db_hostname' parameter.
Immediate actions
Upgrade InvoicePlane to 1.7.2 or later.
Threat Hunt
Unauthorized POST requests to setup configuration endpoint.
Data: Web server access logs
Mitigations
Restrict access to /setup/ directory via WAF or web server configuration.
CVE-2026-40297
Detection coverage 1
Detect CVE-2026-40297 Exploitation - Configuration Injection in InvoicePlane
highDetects exploitation attempts against CVE-2026-40297 by identifying malicious newline character injection in the db_hostname parameter during the setup database configuration step.
Detection queries are available on the platform. Get full rules →