Skip to content
THREATWIRE

CVE

CriticalPoC Available

CVE-2026-40281

Gotenberg ExifTool argument injection

Unauthenticated argument injection in Gotenberg 8.30.1 and earlier. A public repository exists. The vendor advisory describes file move, overwrite, and link creation inside the container, not confirmed code execution.

CVSS
10
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
Class
Other
Status
PoC Available
KEV
Not in CISA KEV
0-day
No
Vendor
Gotenberg
Products
Gotenberg
Affected
Gotenberg 8.30.1 and earlier. The 8.30.1 key check did not cover metadata values.
Fixed
Gotenberg 8.31.0
Published
6 May 2026
Updated
5 Oct 2026

The status above is the claim. Links do not upgrade it.

CVE-2026-40281 is an argument-injection bug in the Gotenberg metadata write path. Versions 8.30.1 and earlier pass metadata values to ExifTool without the same check that was added for metadata keys. NVD scores it 10.0. No authentication is required, and the issue is reachable over the network.

The vendor advisory and NVD describe the effect as control of ExifTool arguments such as file name, directory, and link tags. An attacker can move or overwrite a PDF being processed, or create links, at a path inside the container. That is integrity and availability impact. The published CVSS vector has no confidentiality impact.

A public GitHub repository, created on 2 October 2026, presents the issue as code execution. ThreatWire marks PoC Available because that repository exists. It does not mark Exploit Available or Active Exploitation. CISA has not listed this CVE in the KEV catalog. The fix, 8.31.0, was already published when that repository appeared, so this is not a 0-day.

ThreatWire does not republish the request that demonstrates the bug. Upgrade exposed Gotenberg instances to 8.31.0 or later.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-40281