Skip to content

Known CVE

Gotenberg - Command Injection

Gotenberg < 8.31.0 contains a command injection caused by lack of validation on JSON metadata keys in /forms/pdfengines/metadata/write endpoint, letting unauthenticated attackers execute OS commands, exploit requires crafted HTTP request.

CVE-2026-42589

Critical2026CVSS 9.8CWE-78

cve2026 · gotenberg · exiftool · rce · unauth · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website