CVE-2026-33530 | InvenTree up to 1.2.5 API Endpoint /api/part/ filters information exposure (GHSA-m8j2-vfmq-p6qg)
A vulnerability, which was classified as problematic, was found in InvenTree up to 1.2.5. The impacted element is an unknown function of the file /api/part/ of the component API Endpoint. The manipulation of the argument filters results in exposure of sensitive information through data queries.
This vulnerability is reported as CVE-2026-33530. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.