{"id":"CVE-2025-0474","summary":"Invoice Ninja PDF Rendering Server Side Request Forgery","details":"Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user.\nThis issue affects Invoice Ninja: from 5.8.56 through 5.11.23.","modified":"2026-08-12T03:51:25.555288932Z","published":"2025-01-14T18:50:30.331Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/0xxx/CVE-2025-0474.json"},"references":[{"type":"WEB","url":"https://github.com/invoiceninja/invoiceninja/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/0xxx/CVE-2025-0474.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-0474"},{"type":"ADVISORY","url":"https://vulncheck.com/advisories/invoice-ninja-ssrf"},{"type":"FIX","url":"https://github.com/invoiceninja/invoiceninja/commit/2a9bf353b432d7060e85487b617151ecbc36247d"},{"type":"FIX","url":"https://github.com/invoiceninja/invoiceninja/compare/97ae948618230c1812f3223b80bf22dcb0382dc5..435780932fe19063001d79ba518815df62773d71"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/invoiceninja/invoiceninja","events":[{"introduced":"5b19bf9bcac31069820a1e1125b5b91f04af4788"},{"fixed":"2e97cc84eac51eb743fbac93168764e84e938ee7"},{"fixed":"2a9bf353b432d7060e85487b617151ecbc36247d"}],"database_specific":{"extracted_events":[{"introduced":"5.8.56"},{"fixed":"5.11.23"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v5.11.22","v5.11.21","v5.11.20","v5.11.19","v5.11.18","v5.11.17","v5.11.16","v5.11.15","v5.11.14","v5.11.13","v5.11.12","v5.11.11","v5.11.10","v5.11.9","v5.11.8","v5.11.7","v5.11.6","v5.11.5","v5.11.4","v5.11.3","v5.11.2","v5.11.1","v5.11.0","v5.10.62","v5.10.61","v5.10.60","v5.10.59","v5.10.58","v5.10.57","v5.10.56","v5.10.55","v5.10.54","v5.10.53","v5.10.52","v5.10.51","v5.10.50","v5.10.49","v5.10.48","v5.10.47","v5.10.46","v5.10.45","v5.10.44","v5.10.43","v5.10.42","v5.10.41","v5.10.40","v5.10.39","v5.10.38","v5.10.37","v5.10.36","v5.10.35","v5.10.34","v5.10.33","v5.10.32","v5.10.31","v5.10.30","v5.10.29","v5.10.28","v5.10.27","v5.10.26","v5.10.25","v5.10.24","v5.10.23","v5.10.22","v5.10.21","v5.10.20","v5.10.19","v5.10.18","v5.10.17","v5.10.16","v5.10.15","v5.10.14","v5.10.13","v5.10.12","v5.10.11","v5.10.10","v5.10.9","v5.10.8","v5.10.7","v5.10.6","v5.10.5","v5.10.4","v5.10.3","v5.10.2","v5.10.1","v5.10.0","v5.9.9","v5.9.8","v5.9.7","v5.9.6","v5.9.5","v5.9.4","v5.9.3","v5.9.2","v5.9.1","v5.9.0","v5.8.57","v5.8.56","5.8.56"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-0474.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}