PT-2024-22317 · Unknown · Weasyprint

·

CVE-2024-28184

·

Published

2024-03-08

·

Updated

2026-07-07

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WeasyPrint versions 61.0 through 61.1
Description WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if url fetcher is configured to prevent access to files and URLs.
Recommendations For WeasyPrint versions 61.0 through 61.1, update to version 61.2 to resolve the issue. As a temporary workaround, check that no PDF attachment is defined in source HTML. Launch WeasyPrint in a sandbox that prevents access to the filesystem and the network.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-28184
GHSA-35JJ-WX47-4W8R
PYSEC-2026-2033

Affected Products

Weasyprint