---
id: CVE-2024-21527
title: >-
  Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before
  8.1.0; versions of the package
  github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions
  of the package github.com/gotenberg/gotenberg/v8/…
summary: >-
  Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before
  8.1.0; versions of the package
  github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions
  of the package github.com/gotenberg/gotenberg/v8/…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-918
published: '2024-07-19'
updated: '2026-07-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-21527'
references:
  - url: 'https://gist.github.com/filipochnik/bc88a3d1cc17c07cec391ee98e1e6356'
    label: report@snyk.io
  - url: >-
      https://github.com/gotenberg/gotenberg/commit/ad152e62e5124b673099a9103eb6e7f933771794
    label: report@snyk.io
  - url: 'https://github.com/gotenberg/gotenberg/releases/tag/v8.1.0'
    label: report@snyk.io
  - url: >-
      https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGOTENBERGGOTENBERGV8PKGGOTENBERG-7537081
    label: report@snyk.io
  - url: >-
      https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGOTENBERGGOTENBERGV8PKGMODULESCHROMIUM-7537082
    label: report@snyk.io
  - url: >-
      https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGOTENBERGGOTENBERGV8PKGMODULESWEBHOOK-7537083
    label: report@snyk.io
  - url: 'https://gist.github.com/filipochnik/bc88a3d1cc17c07cec391ee98e1e6356'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/gotenberg/gotenberg/commit/ad152e62e5124b673099a9103eb6e7f933771794
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/gotenberg/gotenberg/releases/tag/v8.1.0'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGOTENBERGGOTENBERGV8PKGGOTENBERG-7537081
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGOTENBERGGOTENBERGV8PKGMODULESCHROMIUM-7537082
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGOTENBERGGOTENBERGV8PKGMODULESWEBHOOK-7537083
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00574
epssPercentile: 0.4506
ingestedAt: '2026-07-02T16:39:34.555Z'
---

## Overview

Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/webhook before 8.1.0 are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when a request is made to a file via localhost, such as <iframe src="\\localhost/etc/passwd">. By exploiting this vulnerability, an attacker can achieve local file inclusion, allowing of sensitive files read on the host system. WorkaroundAn alternative is using either or both --chromium-deny-list and --chromium-allow-list flags.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
