CVE-2026-40281
Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix) in github.com/gotenberg/gotenberg
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/gotenberg/gotenberg/security/advisories/GHSA-q7r4-hc83-hf2q, https://nvd.nist.gov/vuln/detail/CVE-2026-40281, https://github.com/gotenberg/gotenberg/commit/405f1069c026bb08f319fb5a44e5c67c33208318, https://github.com/gotenberg/gotenberg/releases/tag/v8.31.0