CVE-2026-42589

Published May 14, 2026

Last updated 5 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-42589 is an OS command injection vulnerability affecting Gotenberg, a Docker-powered stateless API for PDF files, in versions prior to 8.31.0. The issue is located in the `/forms/pdfengines/metadata/write` HTTP endpoint, which accepts a JSON metadata object and passes its keys directly to ExifTool via the `go-exiftool` library. Because the application does not validate key characters, an unauthenticated attacker can embed a newline character (`\n`) into a JSON key. This embedded newline splits the ExifTool stdin stream, allowing the attacker to inject arbitrary ExifTool flags. By injecting flags such as `-if`, which evaluates Perl expressions, the attacker can execute arbitrary operating-system commands within the Gotenberg environment. Exploitation can bypass basic HTTP-status monitoring because the endpoint still returns a valid PDF and an HTTP 200 status code. The vulnerability is addressed in Gotenberg version 8.31.0.

Description
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No validation is performed on key characters. A \n embedded in a JSON key splits the ExifTool stdin stream into a new argument line, allowing an attacker to inject arbitrary ExifTool flags โ€” including -if, which evaluates Perl expressions. This achieves unauthenticated OS command execution in a single HTTP request. The response is HTTP 200 with a valid PDF, making the attack transparent to basic monitoring. This vulnerability is fixed in 8.31.0.
Source
security-advisories@github.com
NVD status
Analyzed
Products
gotenberg

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-78

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

10

Configurations