CVE-2026-33531 | InvenTree up to 1.2.5 Template report.py encode_svg_image/asset/uploaded_image sql injection (GHSA-rhc5-7c3r-c769)
A vulnerability marked as critical has been reported in InvenTree up to 1.2.5. Impacted is the function encode_svg_image/asset/uploaded_image of the file src/backend/InvenTree/report/templatetags/report.py of the component Template Handler. Performing a manipulation results in sql injection.
This vulnerability is identified as CVE-2026-33531. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.