CVE-2026-40893 PUBLISHED

Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Move

Assigner: GitHub_M
Reserved: 15.04.2026 Published: 14.05.2026 Updated: 14.05.2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly FileName, so System:FileName slips right through and ExifTool happily renames the file. This allows remote attackers to move, rename, and change permissions for arbitrary files. This vulnerability is fixed in 8.31.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
CVSS Score: 8.2

Product Status

Vendor gotenberg
Product gotenberg
Versions
  • Version < 8.31.0 is affected

References

Problem Types

  • CWE-73: External Control of File Name or Path CWE
  • CWE-184: Incomplete List of Disallowed Inputs CWE