Junglewise Threat Intelligence

CVE-2026-44829: Gotenberg path traversal via Windows-style separators in ZIP entry names

CVE-2026-44829 · Severity: high · CVSS 8.8 · Published 2026-05-29

Technologies: Gotenberg, github.com/gotenberg/gotenberg/v8 (Go), github.com/gotenberg/gotenberg/v7 (Go). Vendors: Gotenberg, Go.

Executive brief

Gotenberg, a tool for converting and manipulating documents, is vulnerable to a path traversal flaw when generating ZIP files. An attacker can provide a specially crafted filename that, when processed and returned in a ZIP archive, can cause files to be written to unintended locations on a Windows user's computer during extraction. This could lead to the overwriting of sensitive system files or the placement of malicious software if a user extracts the resulting archive.

Technical details

A path traversal vulnerability exists in Gotenberg due to improper sanitization of multipart filenames containing Windows-style backslash ('\') separators. Because Gotenberg typically runs in Linux containers, 'filepath.Base' fails to strip backslashes, allowing them to persist in the internal 'diskToOriginal' map. When Gotenberg generates a ZIP archive for multi-output routes (such as /split or /convert), these backslashes are included in the ZIP entry names. When a Windows user extracts this ZIP using standard tools (Windows Explorer, 7-Zip, WinRAR), the backslashes are interpreted as path separators, allowing files to be written outside the intended extraction directory. The vulnerability is patched in version 8.33.0.

Affected products

  • Gotenberg Gotenberg <= 8.32.0

Timeline

  • 2026-05-29: advisory: GHSA-hwc4-gmrw-5222 published
  • 2026-05-29: patched: Version 8.33.0 released

References

Related threats