Skip to content
CVE 2026 40281 Exploit

CVE 2026 40281 Exploit

github.com • October 5, 2026

Gotenberg is a Docker-powered stateless API for converting documents to PDF. It exposes a /forms/pdfengines/metadata/write endpoint that allows writing metadata into PDF files*.

This repository contains a proof-of-concept exploit for CVE-2026-40281 , a critical argument injection vulnerability in Gotenberg versions 8.30.1 and earlier . The flaw allows an unauthenticated attacker to execute arbitrary operating system commands on the Gotenberg container through a single HTTP request.

🚨 Note: The vulnerability was disclosed on May 6, 2026, and assigned a CVSS score of 9.1 (NVD) / 10.0 (GitHub Advisory). It is a bypass of the incomplete key-sanitization fix introduced in v8.30.1 (commit 405f106 ).

🚨 Note: The vulnerability was disclosed on May 6, 2026, and assigned a CVSS score of 9.1 (NVD) / 10.0 (GitHub Advisory). It is a bypass of the incomplete key-sanitization fix introduced in v8.30.1 (commit 405f106 ).

🔍 Vulnerability Details

Gotenberg's metadata write endpoint validates metadata keys for control characters but leaves metadata values unvalidated . When metadata is passed to ExifTool, a newline character inside a metadata value splits the ExifTool stdin line into two separate arguments. This allows an attacker to inject arbitrary ExifTool pseudo-tags such as -FileName , -Directory , -SymLink , and -HardLink .

Furthermore, by injecting an advanced formatting expression using qx() (Perl's quote-execute operator), an attacker can execute arbitrary OS commands and read the output from the returned PDF.

🎯 Attacker sends a crafted POST request to /forms/pdfengines/metadata/write with a PDF file and a metadata JSON payload.

💥 The Title metadata value contains a literal newline followed by an ExifTool advanced formatting expression: -Title .

🐚 ExifTool reads the metadata from stdin; the newline terminates the current argument and starts a new one, executing the injected qx() command.

📄 The command output is embedded into the returned PDF, which the attacker can extract.

🐍 Python 3.6+ installed

📦 pip package manager

🌐 Network access to the target Gotenberg instance

🔽 Step 1 — Clone the Repository

📥 Step 2 — Install Dependencies

Option A — Using requirements.txt (recommended):

Option B — Manual installation:

✅ Step 3 — Verify Installation

You should see the banner and usage information.

The exploit supports two modes: automatic detection + interactive shell , and single command execution .

🖥️ Interactive Shell (Default)

If the target is vulnerable, the tool automatically drops into an interactive shell:

🎯 Single Command Execution

🔒 SSL Notice: Certificate verification is disabled by default ( verify=False ) to support self-signed certificates commonly found in internal deployments.

🔒 SSL Notice: Certificate verification is disabled by default ( verify=False ) to support self-signed certificates commonly found in internal deployments.

📝 Command-Line Options

Upgrade to Gotenberg v8.31.0 or later , which validates metadata values in addition to metadata keys.

🚧 Interim Mitigations

🔐 Restrict network access to the Gotenberg API to trusted internal services.

🧱 Deploy a WAF rule blocking newline characters ( \n , \r ) in multipart metadata fields.

👁️ Monitor ExifTool process spawns from the Gotenberg container.

📁 Repository Structure

📜 GitHub Security Advisory GHSA-q7r4-hc83-hf2q

🏛️ NVD - CVE-2026-40281

🚀 Gotenberg v8.31.0 Release

🐹 Go Vulnerability Database GO-2026-5572

This tool is provided for educational and authorized security testing purposes only . Unauthorized access to systems you do not own or have explicit permission to test is illegal and unethical. The author assumes no liability for any misuse or damage caused by this tool. Always obtain proper authorization before testing.

This project is licensed under the MIT License — see the LICENSE file for details.

⭐ If you find this useful, please star the repository! ⭐

Extracted Entities

Attack Types (1)

Companies (1)

Tools (2)