Skip to content
THREATWIRE

News

The Gotenberg public PoC is not a confirmed RCE

CVE-2026-40281 has a public repository and a CVSS 10.0 score. The vendor advisory describes unauthenticated file move, overwrite, and link creation inside the container. Code execution is not the published impact.

Critical

Published 5 Oct 2026 · Updated 5 Oct 2026

What happened

CVE-2026-40281 is an argument-injection bug in Gotenberg, the Docker API that builds PDFs. GitHub advisory GHSA-q7r4-hc83-hf2q, published 30 April 2026 and assigned CWE-88, says versions 8.30.1 and earlier check metadata keys and leave metadata values unsanitized on the way to ExifTool. NVD records the issue as published on 6 May 2026.

The 8.30.1 release had already tried to block dangerous keys. The advisory says that check was incomplete because values were still passed through. Gotenberg 8.31.0 is the release that sanitizes those values, drops System: tags, and blocks the argument smuggling.

Who is affected

Anything still running Gotenberg 8.30.1 or older is in the affected range. The advisory’s CVSS 3.1 score is 10.0, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H. The network path needs no account and no click. Confidentiality is scored none. Integrity and availability are scored high, and the scope is changed, which matches impact inside the container rather than a measured leak of file contents.

The 8.31.0 notes also tell operators to pull gotenberg/gotenberg. The older thecodingmachine/gotenberg image name stopped being published in that release.

What is confirmed

The vendor outcome is file control inside the container while a PDF is processed: an unauthenticated caller can move or rename the file being handled, overwrite files, or create links at paths inside that filesystem. A public repository, MRdark-ops/CVE-2026-40281-exploit, has been online since 2 October 2026. That is enough for PoC Available. It is not a CISA KEV listing. The fix shipped before that repository appeared, so this is not a 0-day.

What is not confirmed

The repository description says code execution. That sentence is the repository’s claim. It is not the impact in the Gotenberg advisory or in the NVD text, which stay on argument injection and file operations inside the container. ThreatWire does not upgrade the class to remote code execution to match the repository title. CISA has not listed the CVE.

What to do

Exposed instances should move to 8.31.0 or later and use the gotenberg/gotenberg image. The request used to demonstrate the bug is not reprinted here.

Sources: Gotenberg advisory GHSA-q7r4-hc83-hf2q, the 8.31.0 release notes, NVD, and the public repository linked from the CVE record.

Related CVEs

Sources

Share on X@threatwire_https://www.threatwire.tech/news/gotenberg-public-poc-is-not-a-confirmed-rce