Security Flaw in FacturaScripts Library Module Allows Exposure of Sensitive Metadata
CVE-2026-27892
6.5MEDIUM
What is CVE-2026-27892?
The Library module in FacturaScripts, an open-source accounting and invoicing software, has a vulnerability that allows authenticated users to download images without any sanitization of embedded metadata. This results in the unfiltered presentation of sensitive information, including GPS coordinates and device details, to anyone with download access. For example, an employee uploading a personal image could unintentionally reveal their home address. This vulnerability specifically affects versions of FacturaScripts released prior to 2026 and has been remedied in the latest update.
Affected Version(s)
facturascripts < 2026
