Junglewise Threat Intelligence

CVE-2026-40893: Gotenberg arbitrary file manipulation via ExifTool tag bypass

CVE-2026-40893 · Severity: high · CVSS 8.2 · Published 2026-05-14

Technologies: Gotenberg, github.com/gotenberg/gotenberg/v8 (Go), github.com/gotenberg/gotenberg/v7 (Go). Vendors: Gotenberg, Go.

Executive brief

Gotenberg is a service used to convert various document formats into PDF files. A security flaw allows unauthenticated remote attackers to bypass safety restrictions and rename, move, or change the permissions of files on the server. This could lead to service disruptions or allow an attacker to place malicious files in shared storage areas used by other applications.

Technical details

Gotenberg utilizes ExifTool to process document metadata but fails to properly sanitize group-prefixed tag names. While the application attempts to block dangerous tags like 'FileName' and 'Directory', it uses a simple string comparison that does not account for ExifTool's support for group prefixes (e.g., 'System:FileName'). An attacker can bypass the blocklist by prepending 'System:' to restricted tags or by using the 'FilePermissions' tag, which was entirely omitted from the blocklist. This allows for arbitrary file manipulation (move/rename/chmod) within the container environment. The vulnerability is reachable via any endpoint that accepts the 'metadata' field, such as PDF conversion or merging routes.

Affected products

  • Gotenberg Gotenberg < 8.31.0

Timeline

  • 2026-05-01: advisory: GitHub Security Advisory published
  • 2026-05-14: disclosed: CVE published to NVD
  • 2026-05-14: patched: Fixed in version 8.31.0

References

Related threats