


Perceptive Security
SOC/SIEM Consultancy

Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control chara…
Published:
5 mei 2026 om 22:00:00
Alert date:
6 mei 2026 om 22:04:36
Source:
nvd.nist.gov
Web Technologies, Cloud & Virtualization
Gotenberg, a Docker-powered stateless API for PDF files, contains a vulnerability in versions 8.30.1 and earlier where the metadata write endpoint validates metadata keys but leaves values unsanitized. An attacker can inject newline characters in metadata values to split ExifTool stdin lines and inject arbitrary pseudo-tags like -FileName, -Directory, -SymLink, and -HardLink. This bypasses the incomplete key-sanitization fix from v8.30.1. Unauthenticated attackers can rename, move, or overwrite arbitrary files in the container filesystem and create symlinks or hard links at arbitrary paths.
Technical details
Mitigation steps:
Affected products:
Gotenberg
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40281
https://github.com/gotenberg/gotenberg/commit/405f1069c026bb08f319fb5a44e5c67c33208318
https://github.com/gotenberg/gotenberg/security/advisories/GHSA-q7r4-hc83-hf2q
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
