Input validation error in gotenberg - #VU129643

 

Input validation error in gotenberg - #VU129643

Published: May 5, 2026


Vulnerability identifier: #VU129643
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify file permissions.

The vulnerability exists due to improper input validation in the ExifTool metadata tag blocklist when handling metadata fields in HTTP requests. A remote attacker can send a specially crafted request using the FilePermissions tag to modify file permissions.

The FilePermissions tag is not included in the dangerous tag blocklist.


Affected software

gotenberg

Remediation

Install security update from vendor's website.

gotenberg - update to 8.31.0

External References

Related Security Bulletins