216.73.217.50

CVE-2026-40893

· Published 14/05/2026 16:16 · Modified 14/05/2026 18:16

Labels: CVE-2026-40893 2026-05-14CVE-2026-40893CWE-73[email protected]

Essential information

Published
14/05/2026 16:16
Modified
14/05/2026 18:16
Author
Creator
CVSS
8.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

CVSS metrics

Description

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly FileName, so System:FileName slips right through and ExifTool happily renames the file. This allows remote attackers to move, rename, and change permissions for arbitrary files. This vulnerability is fixed in 8.31.0.

NVD status

Status
Undergoing Analysis — CVE is currently being analyzed by NVD staff, this process results in association of reference link tags, CVSS scores, CWE association, and CPE applicability statements.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
gotenberg / gotenberg cpe:2.3:a:gotenberg:gotenberg:<8.31.0:*:*:*:*:*:*

References