PatchSiren cyber security CVE debrief
CVE-2017-6100 Tcpdf Project CVE debrief
CVE-2017-6100 describes a high-severity TCPDF issue in versions before 6.2.0 where server-side files used during PDF generation can be uploaded to an external FTP destination. NVD rates the flaw as network-exploitable with no privileges or user interaction and a high confidentiality impact. If your environment uses TCPDF 6.1.1 or earlier, treat this as a priority upgrade and review any PDF workflows that can trigger outbound FTP transfer.
- Vendor
- Tcpdf Project
- Product
- Tcpdf
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-23
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-23
- Advisory updated
- 2026-05-13
Who should care
Application teams and operators that embed TCPDF for server-side PDF generation; developers maintaining PHP applications with TCPDF dependencies; security teams that manage outbound network controls and data-loss prevention for web servers.
Technical summary
The official NVD record maps CVE-2017-6100 to tcpdf versions through 6.1.1 and assigns CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 High). The described behavior is that TCPDF before 6.2.0 uploads files from the server generating PDF files to an external FTP location, which creates a confidentiality exposure path. NVD also classifies the weakness as CWE-668.
Defensive priority
High. The issue is remotely reachable, requires no privileges or user interaction, and is rated for high confidentiality impact, so affected deployments should be patched quickly and monitored for unexpected outbound FTP activity.
Recommended defensive actions
- Upgrade TCPDF to 6.2.0 or later.
- Inventory applications and services that depend on TCPDF and confirm the deployed version is not 6.1.1 or earlier.
- Review PDF-generation code paths and configurations for any FTP or other outbound file-transfer behavior.
- Restrict or monitor outbound FTP egress from servers that generate PDFs.
- Check server logs and network telemetry for unexpected file-transfer activity from PDF-generation hosts.
Evidence notes
This debrief is based on the official CVE/NVD record and the linked references supplied in the corpus. The source description states that tcpdf before 6.2.0 uploads files from the server generating PDF files to an external FTP destination. NVD lists vulnerable CPE coverage through 6.1.1 and provides the CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N with CWE-668. Supporting references include the oss-security mailing list post, Debian bug 814030, and SourceForge bug 1005.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-6100 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-6100
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-6100 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6100
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://sourceforge.net/p/tcpdf/bugs/1005/
[email protected] - Issue Tracking, Patch, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.