Junglewise Threat Intelligence

GO-2026-5587 - Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tags in github.com/gote

Severity: info · Published 2026-06-25

Technologies: github.com/gotenberg/gotenberg/v8 (Go), github.com/gotenberg/gotenberg/v7 (Go). Vendors: Go.

Executive brief

Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tags in github.com/gotenberg/gotenberg

Affected products

  • Go github.com/gotenberg/gotenberg/v8
  • Go github.com/gotenberg/gotenberg/v7

Related threats