Known CVE
Gotenberg - Command Injection
Gotenberg < 8.31.0 contains a command injection caused by lack of validation on JSON metadata keys in /forms/pdfengines/metadata/write endpoint, letting unauthenticated attackers execute OS commands, exploit requires crafted HTTP request.
CVE-2026-42589
Critical2026CVSS 9.8CWE-78
cve2026 · gotenberg · exiftool · rce · unauth · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website