CVE-2019-18958: Gonitro Nitro Pro

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation on the JPEG output of a scanner. Reportedly, this can have a security risk if debug.log is later edited and then executed.

Affected products

  • Gonitro Nitro Pro: before 13.2 (fixed in 13.2)

Published 2019-11-21. Last modified 2026-06-17.