漏洞描述
Gotenberg through 8.30.1 sanitizes only the keys of the JSON metadata submitted to the PDF metadata write endpoint, leaving the values unvalidated. A newline inside a metadata value is written straight to the ExifTool process standard input, where it terminates the current argument and starts a new one, letting an unauthenticated attacker inject arbitrary ExifTool arguments and execute operating system commands through an advanced formatting expression.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/gotenberg/gotenberg/security/advisories/GHSA-q7r4-hc83-hf2q↗github.comhttps://github.com/gotenberg/gotenberg/commit/405f1069c026bb08f319fb5a44e5c67c33208318↗github.comhttps://github.com/gotenberg/gotenberg/releases/tag/v8.31.0↗github.comhttps://github.com/vulhub/vulhub/tree/master/gotenberg/CVE-2026-40281↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40281↗