Executive brief
Gotenberg, a tool for converting and manipulating documents, is vulnerable to a path traversal flaw when generating ZIP files. An attacker can provide a specially crafted filename that, when processed and returned in a ZIP archive, can cause files to be written to unintended locations on a Windows user's computer during extraction. This could lead to the overwriting of sensitive system files or the placement of malicious software if a user extracts the resulting archive.
Technical details
A path traversal vulnerability exists in Gotenberg due to improper sanitization of multipart filenames containing Windows-style backslash ('\') separators. Because Gotenberg typically runs in Linux containers, 'filepath.Base' fails to strip backslashes, allowing them to persist in the internal 'diskToOriginal' map. When Gotenberg generates a ZIP archive for multi-output routes (such as /split or /convert), these backslashes are included in the ZIP entry names. When a Windows user extracts this ZIP using standard tools (Windows Explorer, 7-Zip, WinRAR), the backslashes are interpreted as path separators, allowing files to be written outside the intended extraction directory. The vulnerability is patched in version 8.33.0.
Affected products
- Gotenberg Gotenberg <= 8.32.0
Timeline
- 2026-05-29: advisory: GHSA-hwc4-gmrw-5222 published
- 2026-05-29: patched: Version 8.33.0 released
References
- https://api.github.com/users/Curly-Haired-Baboon
- https://github.com/Curly-Haired-Baboon
- https://api.github.com/users/Curly-Haired-Baboon/gists%7B/gist_id%7D
- https://api.github.com/users/Curly-Haired-Baboon/repos
- https://avatars.githubusercontent.com/u/227850795?v=4
- https://api.github.com/users/Curly-Haired-Baboon/events%7B/privacy%7D