top of page
perceptive_background_267k.jpg

Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control chara…

Published:

5 mei 2026 om 22:00:00

Alert date:

6 mei 2026 om 22:04:36

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Cloud & Virtualization

Gotenberg, a Docker-powered stateless API for PDF files, contains a vulnerability in versions 8.30.1 and earlier where the metadata write endpoint validates metadata keys but leaves values unsanitized. An attacker can inject newline characters in metadata values to split ExifTool stdin lines and inject arbitrary pseudo-tags like -FileName, -Directory, -SymLink, and -HardLink. This bypasses the incomplete key-sanitization fix from v8.30.1. Unauthenticated attackers can rename, move, or overwrite arbitrary files in the container filesystem and create symlinks or hard links at arbitrary paths.

Technical details

Mitigation steps:

Affected products:

Gotenberg

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page