AI description
CVE-2026-40281 is a vulnerability affecting Gotenberg, a Docker-powered stateless API used for PDF file processing, in versions 8.30.1 and earlier. The issue resides in the metadata write endpoint, which validates metadata keys for control characters but leaves metadata values unsanitized. By inserting a newline character into a metadata value, an attacker can split the ExifTool stdin line into two separate arguments. This allows the injection of arbitrary ExifTool pseudo-tags, such as `-FileName`, `-Directory`, `-SymLink`, and `-HardLink`, bypassing a previous key-sanitization fix introduced in version 8.30.1. Exploitation of this flaw allows an unauthenticated attacker to manipulate files within the container filesystem. Specifically, they can rename or move any PDF currently being processed to an arbitrary path, overwrite existing files, or create symlinks and hard links at arbitrary locations.
- Description
- Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata value splits the ExifTool stdin line into two separate arguments, allowing injection of arbitrary ExifTool pseudo-tags such as -FileName, -Directory, -SymLink, and -HardLink. This is a bypass of the incomplete key-sanitization fix introduced in v8.30.1. An unauthenticated attacker can rename or move any PDF being processed to an arbitrary path in the container filesystem, overwrite arbitrary files, or create symlinks and hard links at arbitrary paths.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- gotenberg
CVSS 3.1
- Type
- Primary
- Base score
- 9.1
- Impact score
- 5.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-88
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
7
๐จ Public exploit released for CVE-2026-40281 affecting Gotenberg https://t.co/4PhmHWbVme A proof-of-concept exploit has been published for CVE-2026-40281, a critical unauthenticated remote code execution vulnerability affecting Gotenberg versions prior to 8.31.0. The flaw h
@DarkWebInformer
3 Oct 2026
3884 Impressions
1 Retweet
7 Likes
2 Bookmarks
1 Reply
0 Quotes
#ExploitGrid Daily Digest ๐จ Top Exploits: CVE-2026-40281 (CVSS: 10) gotenberg CVE-2026-40281 (CVSS: 10) gotenberg CVE-2026-40281, CVE-2026-42589 (CVSS: 9.9) gotenberg CVE-2017-7921 (CVSS: 9.8) n/a CVE-2026-103752 (CVSS: 9.8) ..๐งต๐
@exploitgrid
3 Oct 2026
79 Impressions
1 Retweet
1 Like
0 Bookmarks
1 Reply
0 Quotes
Unpopular opinion: The cybersecurity industry is selling you dashboards. Perfect Score Exploit: Gotenberg CVE-2026-40281 Achieves CVSS 10.0 With Unauthenticated RCE
@lyrie_ai
6 Jun 2026
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:thecodingmachine:gotenberg:*:*:*:*:*:*:*:*",
"matchCriteriaId": "953D4808-E728-472B-94E3-9714C1E2EA1C",
"versionEndExcluding": "8.31.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]