Junglewise Threat Intelligence

CVE-2026-42593: Gotenberg Arbitrary PDF Read via Path Traversal in Conversion Routes

CVE-2026-42593 · Severity: medium · CVSS 5.3 · Published 2026-05-14

Technologies: Gotenberg, github.com/gotenberg/gotenberg/v8 (Go), github.com/gotenberg/gotenberg/v7 (Go). Vendors: Gotenberg, Go.

Executive brief

Gotenberg is a tool used to convert various file formats into PDF documents. A security flaw allows unauthorized users to read sensitive PDF files stored on the server or within the application's environment. By sending a specially crafted request, an attacker can force the system to include local files as 'stamps' or 'watermarks' in a generated PDF, which is then returned to the attacker.

Technical details

A path traversal and external control of filename vulnerability exists in Gotenberg's merge, split, and conversion routes (LibreOffice and Chromium). The application fails to validate the 'stampExpression' and 'watermarkExpression' parameters when 'stampSource' or 'watermarkSource' is set to 'pdf' but no file is actually uploaded. In these cases, the application uses the user-provided file path directly. The underlying 'pdfcpu' engine then opens the file at that path and composites it onto the output PDF returned to the user. This allows an attacker to read any PDF file accessible to the Gotenberg process and can also be used as a file-existence oracle for non-PDF files. The issue is fixed in version 8.32.0.

Affected products

  • Gotenberg Gotenberg < 8.32.0

Timeline

  • 2026-04-30: advisory: GitHub Security Advisory published
  • 2026-05-14: disclosed: CVE published to NVD
  • 2026-05-14: patched: Vulnerability fixed in version 8.32.0

References

Related threats