Image Metadata Exposure in InvoicePlane by InvoicePlane
CVE-2026-39372
4.9MEDIUM
What is CVE-2026-39372?
Prior to version 1.7.2, InvoicePlane allows uploaded image attachments to retain EXIF metadata, which includes sensitive information such as GPS coordinates, timestamps, and device details. This can lead to unintended data exposure, as users can inadvertently share private location information with others. The vulnerability has been addressed in version 1.7.2, emphasizing the importance of keeping software updated.
Affected Version(s)
InvoicePlane < 1.7.2
