Image Processing Vulnerability in Tandoor Recipes by Tandoor
CVE-2026-29055

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
26 March 2026

What is CVE-2026-29055?

Tandoor Recipes, an application designed for managing recipes and meal planning, has a vulnerability in its image processing pipeline. In versions prior to 2.6.0, the application fails to strip EXIF metadata and validate image sizes when users upload images in WebP and GIF formats. This oversight allows sensitive information—including GPS coordinates, camera details, timestamps, and software metadata—to be stored and accessible to every user who views the uploaded recipe. The vulnerability was noted by developers in a comment within the source code. The issue has been resolved in version 2.6.0, which ensures that EXIF data from images does not pose a privacy risk.

Affected Version(s)

recipes < 2.6.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.