Description
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros.
Scores
CVSS v3
9.8
EPSS
0.0058
EPSS Percentile
68.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-459
Status
published
Products (1)
thecodingmachine/gotenberg
< 6.2.1
Published
Jan 07, 2021
Tracked Since
Feb 18, 2026