{"id":"CVE-2025-64012","details":"InvoicePlane commit debb446c is vulnerable to Incorrect Access Control. The invoices/view handler fails to verify ownership before returning invoice data.","modified":"2026-08-12T03:51:24.978242193Z","published":"2025-12-16T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64012.json"},"references":[{"type":"WEB","url":"https://gist.github.com/tarekramm/797073e9ae991211ff2ae71ed1190c7d"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64012.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64012"},{"type":"FIX","url":"https://github.com/InvoicePlane/InvoicePlane/commit/debb446ceaa84efc136987fc1e21b268f34e47b0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/invoiceplane/invoiceplane","events":[{"introduced":"8c76ad0786ca7ca3a0c72d59e54a7392b2d833bd"},{"fixed":"debb446ceaa84efc136987fc1e21b268f34e47b0"}],"database_specific":{"source":["CPE_STRING","REFERENCES"],"cpe":"cpe:2.3:a:invoiceplane:invoiceplane:1.6.1:-:*:*:*:*:*:*","extracted_events":[{"introduced":"1.6.1-NA"},{"last_affected":"1.6.1-NA"}]}}],"versions":["1.6.1-NA","v1.6.3","v1.6.3-rc2","v1.6.3-rc1","v1.6.3-rc0","v1.6.2-beta-3","v1.6.2-beta-2","v1.6.2-beta-1","v1.6.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64012.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}