CVE-2026-39372

Source
https://cve.org/CVERecord?id=CVE-2026-39372
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39372.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-39372
Aliases
  • GHSA-7j67-2v6p-275v
Published
2026-09-25T15:21:53Z
Modified
2026-09-27T03:47:36Z
Severity
  • 4.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
InvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata in Attachments
Details

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores and serves uploaded image attachments without stripping EXIF metadata. When an administrator uploads an image through invoice attachments, quote attachments, or another attachment feature and shares it with another user, the recipient can retrieve embedded GPS coordinates, timestamps, and device information. The preserved metadata can disclose private location and device details across users. This vulnerability is fixed in 1.7.2.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-200",
        "CWE-359"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39372.json"
}
References

Affected packages

Git / github.com/invoiceplane/invoiceplane

Affected ranges

Type
GIT
Repo
https://github.com/invoiceplane/invoiceplane
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "1.7.2"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.9beta
v1.*
v1.0.0
v1.0.1
v1.1.0
v1.2.0
v1.4.0
v1.4.1
v1.4.10
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.4.9
v1.5.0
v1.5.1
v1.5.10
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.5.6
v1.5.7
v1.5.8
v1.5.9
v1.6-beta
v1.6-beta-1
v1.6-beta-2
v1.6-beta-3
v1.6.0
v1.6.1
v1.6.1-alpha-1
v1.6.1-beta-1
v1.6.1-beta-2
v1.6.1-beta-3
v1.6.2-beta-1
v1.6.2-beta-2
v1.6.2-beta-3
v1.6.3
v1.6.3-rc0
v1.6.3-rc1
v1.6.3-rc2
v1.6.4-beta-1
v1.6.5
v1.7.2-beta-1
v1.7.2-rc-1
v1.7.2-rc-2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39372.json"