Medium severity6.1NVD Advisory· Published Aug 26, 2021· Updated Jun 17, 2026
CVE-2020-14161
CVE-2020-14161
Description
It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint.
Affected products
3- Gotenberg/Gotenbergdescription
Patches
Vulnerability mechanics
References
3- github.com/gotenberg/gotenberg/issues/215nvdIssue TrackingPatchThird Party Advisory
- github.com/gotenberg/gotenberg/pull/319nvdPatchThird Party Advisory
- github.com/thecodingmachine/gotenberg/releasesnvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.