/Vulnerability Library

Gotenberg <= 8.30.1 - Remote Code Execution

CVE-2026-40281
Verified

Description

Gotenberg through 8.30.1 sanitizes only the keys of the JSON metadata submitted to the PDF metadata write endpoint, leaving the values unvalidated. A newline inside a metadata value is written straight to the ExifTool process standard input, where it terminates the current argument and starts a new one, letting an unauthenticated attacker inject arbitrary ExifTool arguments and execute operating system commands through an advanced formatting expression.

Severity

Critical

CVSS Score

9.1

Exploit Probability

2%

Affected Product

gotenberg

Published Date

September 28, 2026

Template Author

aryu-ru

CVE-2026-40281.yaml
9.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVE ID:
cve-2026-40281
CWE ID:
cwe-88

References

https://github.com/gotenberg/gotenberg/security/advisories/GHSA-q7r4-hc83-hf2qhttps://github.com/gotenberg/gotenberg/commit/405f1069c026bb08f319fb5a44e5c67c33208318https://github.com/gotenberg/gotenberg/releases/tag/v8.31.0https://github.com/vulhub/vulhub/tree/master/gotenberg/CVE-2026-40281https://nvd.nist.gov/vuln/detail/CVE-2026-40281

Remediation Steps

Update to version 8.31.0 or later, which validates metadata values in addition to metadata keys.