AI description
CVE-2026-42589 is an OS command injection vulnerability affecting Gotenberg, a Docker-powered stateless API for PDF files, in versions prior to 8.31.0. The issue is located in the `/forms/pdfengines/metadata/write` HTTP endpoint, which accepts a JSON metadata object and passes its keys directly to ExifTool via the `go-exiftool` library. Because the application does not validate key characters, an unauthenticated attacker can embed a newline character (`\n`) into a JSON key. This embedded newline splits the ExifTool stdin stream, allowing the attacker to inject arbitrary ExifTool flags. By injecting flags such as `-if`, which evaluates Perl expressions, the attacker can execute arbitrary operating-system commands within the Gotenberg environment. Exploitation can bypass basic HTTP-status monitoring because the endpoint still returns a valid PDF and an HTTP 200 status code. The vulnerability is addressed in Gotenberg version 8.31.0.
- Description
- Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No validation is performed on key characters. A \n embedded in a JSON key splits the ExifTool stdin stream into a new argument line, allowing an attacker to inject arbitrary ExifTool flags โ including -if, which evaluates Perl expressions. This achieves unauthenticated OS command execution in a single HTTP request. The response is HTTP 200 with a valid PDF, making the attack transparent to basic monitoring. This vulnerability is fixed in 8.31.0.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- gotenberg
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-78
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
10
๐จ PoC released for an unauthenticated Gotenberg RCE chain PoC: https://t.co/1GpZySsuWA CVE chain: CVE-2026-42589 + CVE-2026-40281 The exploit targets the /forms/pdfengines/metadata/write endpoint and chains metadata injection flaws to achieve remote command execution. https
@DarkWebInformer
5 Oct 2026
5374 Impressions
4 Retweets
18 Likes
3 Bookmarks
0 Replies
0 Quotes
#ExploitGrid Daily Digest ๐จ Top Exploits: CVE-2026-40281 (CVSS: 10) gotenberg CVE-2026-40281 (CVSS: 10) gotenberg CVE-2026-40281, CVE-2026-42589 (CVSS: 9.9) gotenberg CVE-2017-7921 (CVSS: 9.8) n/a CVE-2026-103752 (CVSS: 9.8) ..๐งต๐
@exploitgrid
4 Oct 2026
151 Impressions
0 Retweets
2 Likes
0 Bookmarks
1 Reply
0 Quotes
#ExploitGrid Daily Digest ๐จ Top Exploits: CVE-2026-40281 (CVSS: 10) gotenberg CVE-2026-40281 (CVSS: 10) gotenberg CVE-2026-40281, CVE-2026-42589 (CVSS: 9.9) gotenberg CVE-2017-7921 (CVSS: 9.8) n/a CVE-2026-103752 (CVSS: 9.8) ..๐งต๐
@exploitgrid
3 Oct 2026
133 Impressions
1 Retweet
2 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-42589 is a CVSS 9.8 unauthenticated RCE in Gotenberg <8.31.0. An attacker can inject ExifTool flags through the metadata endpoint and execute OS commands with a single HTTP request. Public exploits are available. #CyberSecurity #CVE #RCE https://t.co/3MKywgs8WT
@exploitgrid
3 Oct 2026
267 Impressions
2 Retweets
8 Likes
2 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:thecodingmachine:gotenberg:*:*:*:*:*:*:*:*",
"matchCriteriaId": "953D4808-E728-472B-94E3-9714C1E2EA1C",
"versionEndExcluding": "8.31.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]