Gotenberg <= 8.30.1 - Remote Code Execution
CVE-2026-40281
Verified
Description
Gotenberg through 8.30.1 sanitizes only the keys of the JSON metadata submitted to the PDF metadata write endpoint, leaving the values unvalidated. A newline inside a metadata value is written straight to the ExifTool process standard input, where it terminates the current argument and starts a new one, letting an unauthenticated attacker inject arbitrary ExifTool arguments and execute operating system commands through an advanced formatting expression.
Severity
Critical
CVSS Score
9.1
Exploit Probability
2%
Affected Product
gotenberg
Published Date
September 28, 2026
Template Author
aryu-ru
CVE-2026-40281.yaml
9.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVE ID:
cve-2026-40281
CWE ID:
cwe-88
References
https://github.com/gotenberg/gotenberg/security/advisories/GHSA-q7r4-hc83-hf2qhttps://github.com/gotenberg/gotenberg/commit/405f1069c026bb08f319fb5a44e5c67c33208318https://github.com/gotenberg/gotenberg/releases/tag/v8.31.0https://github.com/vulhub/vulhub/tree/master/gotenberg/CVE-2026-40281https://nvd.nist.gov/vuln/detail/CVE-2026-40281
Remediation Steps
Update to version 8.31.0 or later, which validates metadata values in addition to metadata keys.