
🚨 PoC released for an unauthenticated Gotenberg RCE chain PoC: https://github.com/HackfutSecRoot/-GOTENBERG-RCE-CHAIN CVE chain: CVE-2026-42589 + CVE-2026-40281 The exploit targets the /forms/pdfengines/metadata/write endpoint and chains metadata injection flaws to achieve remote command execution. Affected: Gotenberg ≤ 8.30.1 Patched: Gotenberg ≥ 8.31.0 The PoC includes vulnerability detection, interactive command execution, reverse shell support, and multi-target scanning.









