
🚨 Public exploit released for CVE-2026-40281 affecting Gotenberg https://github.com/MRdark-ops/CVE-2026-40281-exploit A proof-of-concept exploit has been published for CVE-2026-40281, a critical unauthenticated remote code execution vulnerability affecting Gotenberg versions prior to 8.31.0. The flaw affects Gotenberg’s PDF metadata handling and can allow a remote attacker to inject commands through crafted metadata values sent to the /forms/pdfengines/metadata/write endpoint. No authentication or user interaction is required. Key details: ⠀ • CVE-2026-40281 • CVSS: 9.1 Critical • Gotenberg < 8.31.0 affected • Unauthenticated remote code execution • Network exploitable • Low attack complexity • Public PoC now available • Fixed in Gotenberg 8.31.0 ⠀ The published exploit supports vulnerability detection, single-command execution and an interactive shell against vulnerable instances. Organizations running affected Gotenberg deployments should upgrade to version 8.31.0 or later. 💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. http://darkwebinformer.com/pricing






