CVE-2026-40281
Gotenberg ExifTool argument injection
Unauthenticated argument injection in Gotenberg 8.30.1 and earlier. A public repository exists. The vendor advisory describes file move, overwrite, and link creation inside the container, not confirmed code execution.
- CVSS
- 10
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
- Class
- Other
- Status
- PoC Available
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Gotenberg
- Products
- Gotenberg
- Affected
- Gotenberg 8.30.1 and earlier. The 8.30.1 key check did not cover metadata values.
- Fixed
- Gotenberg 8.31.0
- CWE
- CWE-88
- Published
- 6 May 2026
- Updated
- 5 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2026-40281 is an argument-injection bug in the Gotenberg metadata write path. Versions 8.30.1 and earlier pass metadata values to ExifTool without the same check that was added for metadata keys. NVD scores it 10.0. No authentication is required, and the issue is reachable over the network.
The vendor advisory and NVD describe the effect as control of ExifTool arguments such as file name, directory, and link tags. An attacker can move or overwrite a PDF being processed, or create links, at a path inside the container. That is integrity and availability impact. The published CVSS vector has no confidentiality impact.
A public GitHub repository, created on 2 October 2026, presents the issue as code execution. ThreatWire marks PoC Available because that repository exists. It does not mark Exploit Available or Active Exploitation. CISA has not listed this CVE in the KEV catalog. The fix, 8.31.0, was already published when that repository appeared, so this is not a 0-day.
ThreatWire does not republish the request that demonstrates the bug. Upgrade exposed Gotenberg instances to 8.31.0 or later.