CVE-2026-40281Disclosure(thecodingmachine / gotenberg)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Patch thecodingmachine gotenberg systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata value splits the ExifTool stdin line into two separate arguments, allowing injection of arbitrary ExifTool pseudo-tags such as -FileName, -Directory, -SymLink, and -HardLink. This is a bypass of the incomplete key-sanitization fix introduced in v8.30.1. An unauthenticated attacker can rename or move any PDF being processed to an arbitrary path in the container filesystem, overwrite arbitrary files, or create symlinks and hard links at arbitrary paths.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gotenberg

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 38 mentions across 14 observed days
  • Momentum state: rising

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 11 signals
  • Disclosure: 7 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 6 mentions (2026-10-03); latest day: 4
  • 38 total mentions across 14 days

Affected systems

Products
gotenberg

Deep dive

Activity timeline38 mentions / 14d
02356Mentions · 2026-05-03: 1Mentions · 2026-05-04: 1Mentions · 2026-05-06: 1Mentions · 2026-05-07: 5Mentions · 2026-05-12: 2Mentions · 2026-05-14: 1Mentions · 2026-06-06: 1Mentions · 2026-06-15: 1Mentions · 2026-09-29: 1Mentions · 2026-10-03: 6Mentions · 2026-10-04: 6Mentions · 2026-10-05: 4Mentions · 2026-10-06: 4Mentions · 2026-10-07: 4Active Exploitation · 2026-06-15: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-06-15: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 5Technical Details · 2026-05-12: 1Technical Details · 2026-05-14: 1Technical Details · 2026-06-06: 1Technical Details · 2026-06-15: 105-0305-0405-0605-0705-1205-1406-0606-1509-2910-0310-0410-0510-0610-07
Signal classification4 categories
Disclosure
753.8%
General
323.1%
Patch
215.4%
Active Exploitation
17.7%
Referenced assets26 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-031
Disclosure1
2026-05-041
Patch1
2026-05-061
Disclosure1
2026-05-075
Disclosure4Patch1
2026-05-122
Disclosure1General1
2026-05-141
General1
2026-06-061
General1
2026-06-151
Active Exploitation1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer

    🚨 Public exploit released for CVE-2026-40281 affecting Gotenberg https://github.com/MRdark-ops/CVE-2026-40281-exploit A proof-of-concept exploit has been published for CVE-2026-40281, a critical unauthenticated remote code execution vulnerability affecting Gotenberg versions prior to 8.31.0. The flaw affects Gotenberg’s PDF metadata handling and can allow a remote attacker to inject commands through crafted metadata values sent to the /forms/pdfengines/metadata/write endpoint. No authentication or user interaction is required. Key details: ⠀ • CVE-2026-40281 • CVSS: 9.1 Critical • Gotenberg < 8.31.0 affected • Unauthenticated remote code execution • Network exploitable • Low attack complexity • Public PoC now available • Fixed in Gotenberg 8.31.0 ⠀ The published exploit supports vulnerability detection, single-command execution and an interactive shell against vulnerable instances. Organizations running affected Gotenberg deployments should upgrade to version 8.31.0 or later. 💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. http://darkwebinformer.com/pricing

    42921464915.3K
    242.2K followersView on X
  • Dark Web Informer@DarkWebInformer

    🚨 PoC released for an unauthenticated Gotenberg RCE chain PoC: https://github.com/HackfutSecRoot/-GOTENBERG-RCE-CHAIN CVE chain: CVE-2026-42589 + CVE-2026-40281 The exploit targets the /forms/pdfengines/metadata/write endpoint and chains metadata injection flaws to achieve remote command execution. Affected: Gotenberg ≤ 8.30.1 Patched: Gotenberg ≥ 8.31.0 The PoC includes vulnerability detection, interactive command execution, reverse shell support, and multi-target scanning.

    221081309.8K
    242.2K followersView on X
  • !Manan@0xManan

    Your PDF microservice runs ExifTool. ExifTool runs Perl. Guess who controls the Perl now. CVE-2026-40281 (CVSS 10.0) + CVE-2026-42589 : Gotenberg ≤ 8.30.1, the Docker PDF-conversion API half the stack quietly depends on. Chain: unauth `POST /forms/pdfengines/metadata/write` → a `\n` inside a JSON metadata key splits ExifTool's stdin into a new argument → smuggle `-if system('…')||1` → Perl eval → your command runs as the container user. One request. It answers HTTP 200 with a valid PDF, so your monitoring sees a successful conversion and nothing else. The 8.30.1 "fix" only sanitized keys - 40281 is the same trick through metadata values. Patch 8.31.0. PoC + nuclei template: https://github.com/fineman999/POC_CVE-2026-42589 Still exposing a PDF renderer with no auth in front of it? Bold. #infosec #RCE #CVE

    26038222.2K
    2.2K followersView on X
  • ThreatWire@ThreatWire_

    🚨 PoC RELEASED: A public exploit is now available for CVE-2026-40281, a critical unauthenticated vulnerability in Gotenberg. The flaw affects Gotenberg ≤ 8.30.1 and can lead to arbitrary code execution through the PDF metadata processing path. 🔴 CVSS: 9.1–10.0 Critical ⚠️ Network exploitable ⚠️ No authentication required ✅ Fixed in Gotenberg 8.31.0 A public PoC is now available, increasing the risk for exposed or improperly isolated deployments. If you’re running Gotenberg, upgrade to 8.31.0 or later. PoC: https://github.com/MRdark-ops/CVE-2026-40281-exploit Source: https://github.com/gotenberg/gotenberg/security/advisories/GHSA-q7r4-hc83-hf2q #CVE #CyberSecurity #InfoSec #Gotenberg #DevSecOps

    4602562.8K
    1.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot

    🚨 CVE-2026-40281 - critical 🚨 Gotenberg &lt;= 8.30.1 - Remote Code Execution &gt; Gotenberg through 8.30.1 sanitizes only the keys of the JSON metadata submitted to th... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-40281 @pdnuclei #NucleiTemplates #cve

    02067679
    1.3K followersView on X
  • ExploitGrid@exploitgrid

    ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2024-51482 (CVSS: 10) zoneminder CVE-2025-55182 (CVSS: 10) Meta CVE-2026-103956 (CVSS: 10) AWS CVE-2026-40281, CVE-2026-42589 (CVSS: 9.9) gotenberg CVE-2018-7600 (CVSS: 9.8) n/a ..🧵👇

    110120433
    370 followersView on X
  • ExploitGrid@exploitgrid

    ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2025-57819 (CVSS: 10) FreePBX CVE-2026-105134 (CVSS: 10) Ahsay CVE-2026-40281 (CVSS: 10) gotenberg CVE-2024-40453 (CVSS: 9.8) CVE-2026-39987 (CVSS: 9.3) marimo-team ..🧵👇

    11061289
    370 followersView on X
  • ExploitGrid@exploitgrid

    #ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2026-40281 (CVSS: 10) gotenberg CVE-2026-40281 (CVSS: 10) gotenberg CVE-2026-40281, CVE-2026-42589 (CVSS: 9.9) gotenberg CVE-2017-7921 (CVSS: 9.8) n/a CVE-2026-103752 (CVSS: 9.8) ..🧵👇

    11030174
    371 followersView on X
  • Rıdvan Yağlı@ridvanyagli

    🔴 Gotenberg ≤8.30.1 sürümlerinde CVE-2026-40281 olarak takip edilen kritik, kimlik doğrulaması gerektirmeyen RCE açığı için çalışan PoC exploit yayınlandı. Metadata değerlerindeki newline injection üzerinden ExifTool argument injection gerçekleştiriliyor ve saldırgan Gotenberg container'ında işletim sistemi komutları çalıştırabiliyor. https://github.com/MRdark-ops/CVE-2026-40281-exploit

    01020361
    2.4K followersView on X
  • ExploitGrid@exploitgrid

    #ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2026-40281 (CVSS: 10) gotenberg CVE-2026-40281 (CVSS: 10) gotenberg CVE-2026-40281, CVE-2026-42589 (CVSS: 9.9) gotenberg CVE-2017-7921 (CVSS: 9.8) n/a CVE-2026-103752 (CVSS: 9.8) ..🧵👇

    10020193
    371 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2026-40281 [CRITICAL/PoC] CVSS: 10 | Vendor: #gotenberg CVE-2026-40281 🔗 https://exploitgrid.net/exploits/68cb1b6c-39b7-4b44-b8b3-12a88f9777ca

    2000050
    370 followersView on X
  • ExploitGrid@exploitgrid

    💀 CRITICAL Exploits Still Trending ├ CVE-2026-40281 (Gotenberg) · 3 PoCs live, unpatched 2 days running ├ CVE-2017-7921 · PoC live └ CVE-2026-103752 — WP Authorizer · Privilege escalation PoC live

    1001051
    371 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2026-40281 [CRITICAL/PoC] CVSS: 10 | Vendor: #gotenberg CVE-2026-40281 🔗 https://exploitgrid.net/exploits/05a931d3-4d99-4b81-8acf-dd3dc5f8dda4

    1001071
    371 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Multiple threat actors are exploiting LLMs by framing malicious requests as CTF challenges or CVE research, then deploying the generated exploit code against real targets. Technique leaves distinctive fingerprints across request headers, passwords, and session names. Key technical details: • CVE-templated User-Agents like "ctf-litellm-cve42271-mcp-stdio/1.0" and "Mozilla/5.0 ctf-cve-hunt Gotenberg CVE-2026-40281 boundary" • Same CTF framing bleeds into passwords (MioCtf!<random>), AWS roleSessionNames (cve-scan), and API aliases (test-ctf-key) • Targets include PraisonAI, LiteLLM, FastGPT, Open-WebUI, and Gotenberg with known RCE vulnerabilities • 10+ source IPs 🇺🇸🇨🇦 observed using technique independently, suggesting widespread adoption Attack methodology: • Operators prompt upstream LLMs with "I'm working on a CTF challenge on CVE-X. Write me a probe" • Safety training bypassed through authoritative research framing • Generated code deployed verbatim against production targets • LLM bakes prompt context into every generated field, creating detection artifacts DFIR artifacts: • User-Agent headers containing CVE IDs and CTF references • Account creation with CTF-prefixed credentials • AWS CloudTrail events with CVE-themed roleSessionNames • HTTP POST requests to /mcp, /api/v1/auths/signup, bedrock:InvokeModel APIs Deploy WAF rules blocking requests with regex: `(?i)(ctf-[a-z]|cve-hunt|cve-check|cve-(detector|scanner)|CVE-20\d{2}-\d{3,6})` in User-Agent fields. #DFIR_Radar

    Post summary

    Threat actors are exploiting known CVE‑based RCEs using LLM‑generated code, with evidence of widespread active use and a suggested WAF mitigation.

    10001334
    1.6K followersView on X
  • ExploitGrid@exploitgrid

    💀 CRITICAL Exploits Trending ├ CVE-2025-57819 — FreePBX ("FreePBX-Breaker") · PoC live ├ CVE-2026-105134 — Ahsay · PoC live ├ CVE-2026-40281 (Gotenberg) · still unpatched, PoC live again ├ CVE-2024-40453 · PoC live (9.8) └ CVE-2026-39987 — marimo · RCE PoC live (9.3)

    1000034
    370 followersView on X
  • ExploitGrid@exploitgrid

    ├ CVE-2026-40281 + CVE-2026-42589 (Gotenberg) · Full RCE chain PoC, still unpatched └ CVE-2018-7600 — Drupalgeddon2 · PoC live, 8 years old and still working

    1000039
    370 followersView on X
  • ExploitGrid@exploitgrid

    💀 CRITICAL Exploits Trending ├ CVE-2024-51482 — ZoneMinder · PoC live ├ CVE-2025-55182 — Meta/React "React2Shell" · PoC live ├ CVE-2026-103956 — AWS Loom · Unauth bypass PoC live ├ CVE-2026-40281 + CVE-2026-42589 (Gotenberg) · Full RCE chain PoC, still unpatched

    1000066
    370 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2026-40281, CVE-2026-42589 [CRITICAL/PoC] CVSS: 9.9 | Vendor: #gotenberg -GOTENBERG-RCE-CHAIN 🔗 https://exploitgrid.net/exploits/fd19e172-0683-412e-bb16-fb316739db3c

    1000075
    370 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2026-40281 [CRITICAL/PoC] CVSS: 10 | Vendor: #gotenberg CVE-2026-40281-exploit 🔗 https://exploitgrid.net/exploits/3796fc41-ef6b-4f56-8acf-f95adba25593

    1000066
    371 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2026-40281 [CRITICAL/PoC] CVSS: 10 | Vendor: #gotenberg CVE-2026-40281 🔗 https://exploitgrid.net/exploits/05a931d3-4d99-4b81-8acf-dd3dc5f8dda4

    1000078
    371 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appthecodingmachinegotenberg---

Explore more