CVE-2026-40893
Published: 14 May 2026
Summary
CVE-2026-40893 is a high-severity External Control of File Name or Path (CWE-73) vulnerability. Its CVSS base score is 8.2 (High).
Operationally, it is not currently listed in the CISA KEV catalog.
Threat & Defense Details
Likely Mitigating ControlsAI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Rejects externally supplied file or resource identifiers that fail validity checks.
Spam filters rely on evolving blacklists, signatures, and heuristics of disallowed message patterns; keeping them updated per the control directly mitigates incomplete disallowed-input lists.
NVD Description
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly FileName, so System:FileName slips right through and ExifTool happily renames the file. This allows remote attackers to move, rename, and…
more
change permissions for arbitrary files. This vulnerability is fixed in 8.31.0.
Deeper analysisAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)