CVE-2026-40281 is an argument-injection vulnerability in Gotenberg versions 8.30.1 and earlier. The /forms/pdfengines/metadata/write endpoint validates control characters in JSON metadata keys but does not sanitize metadata values. A newline in a value is passed to ExifTool standard input as a separate argument, enabling injection of ExifTool pseudo-tags including file-name, directory, symbolic-link, and hard-link operations. Injected ExifTool arguments can also contain advanced formatting expressions that execute operating-system commands and return command output in XMP metadata embedded in the generated PDF. The issue bypasses the incomplete key-sanitization fix introduced in version 8.30.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
The supplied repository contains four files: a standalone Python exploit, a Nuclei exploit/detection template, an MIT license, and a README. No original main-file URL was provided, so both implementations were reviewed. The listed file sizes total 21,274 bytes; an archive size and Git reference were not supplied. The repository URL is inferred from the README's clone example, and size_bytes is 0 to indicate unavailable archive metadata. Both implementations target the PDF metadata-write API. They submit a minimal PDF alongside a Title value containing a newline intended to split ExifTool stdin arguments, then introduce an advanced-formatting expression using Perl qx() for command execution. The Python program probes with id, retrieves base64-wrapped output from the returned PDF, and offers an interactive-looking command loop. This is not a persistent shell: each command generates a separate HTTP request, with no maintained working directory or session state. The Nuclei template sends one request and checks status, PDF content type, and uid/gid output; although used for detection, its probe actively attempts command execution and its cmd variable is customizable. Notable limitations include unescaped command interpolation, which can make commands containing certain quotes or Perl syntax unreliable, and a Nuclei matcher that does not decompress PDF streams or generalize to arbitrary command output. The Python client disables TLS verification. No hardcoded callback server, credential theft, destructive local commands, or persistence mechanism appears in the supplied code. The README incorrectly advertises a --cmd option that the Python argument parser does not implement, and references requirements.txt, which is absent from the four-file inventory. Documentation claims versions through 8.30.1 and all 7.x releases are affected, with 8.31.0 fixing metadata-value validation; these claims, the CVE assignment, and exploit reliability were not independently verified. Advisory and badge URLs are documentation references, not exploit runtime destinations.
This four-file repository contains a functional standalone Python 3 exploit, a Nuclei YAML detection template, an MIT license, and a README. The primary file, CVE-2026-40281.py, targets Gotenberg's PDF metadata-write endpoint with a minimal PDF and a malicious metadata Title value. A literal newline terminates an ExifTool stdin argument, enabling injection of a Perl advanced-formatting qx() expression that executes arbitrary commands. The script sends requests with TLS certificate verification disabled, requires HTTP 200 plus an application/pdf response, and extracts randomized base64-delimited command output from either the PDF body or a decompressed PDF stream. It first runs `id` to confirm command execution, then offers an interactive command loop. CVE-2026-40281.yaml is a Nuclei-style detection template that submits a similar request using `id` and matches UID/GID output in a PDF response. The repository is not itself a single framework module; it includes a separate Nuclei template alongside the custom exploit. Notable documentation discrepancies: the README lists a requirements.txt file and a `--cmd` single-command option, but neither exists in the supplied repository/code; the Python tool only accepts `-u`/`--url` and enters its interactive loop after validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Critical unauthenticated remote code execution in Gotenberg's PDF metadata-writing endpoint caused by insufficient sanitization of metadata values, allowing ExifTool argument injection and execution through an advanced formatting expression.
CVE-2026-40281 is referenced as the subject of a template addition and YAML-formatting correction. The content provides no technical details about the flaw, its impact, or affected component.
An unauthenticated argument injection vulnerability in Gotenberg's metadata handling via ExifTool that allows file move/overwrite, path traversal, and related file-system impact inside the container.
A Gotenberg vulnerability referenced in observed scanning or exploit attempts using a second CTF prompt template.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.