CVE-2026-40893

HIGH

Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Move

Title source: cna
STIX 2.1

Description

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly FileName, so System:FileName slips right through and ExifTool happily renames the file. This allows remote attackers to move, rename, and change permissions for arbitrary files. This vulnerability is fixed in 8.31.0.

References (1)

Core 1
Core References

Scores

CVSS v3 8.2
EPSS 0.0035
EPSS Percentile 26.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-184 CWE-73
Status published
Products (3)
gotenberg/gotenberg 0 - 8.30.1Go
gotenberg/gotenberg < 8.31.0
thecodingmachine/gotenberg < 8.31.0
Published May 14, 2026
Tracked Since May 14, 2026