HIGH7.4
PYSEC-2026-2033
WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
Quick fix
PYSEC-2026-2033 — weasyprint: upgrade to the fixed version with the command below.
pip install --upgrade 'weasyprint>=61.2'Details
### Impact Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs.
### Patches Fixed by 734ee8e that’s included in 61.2
### Workarounds - Check that no PDF attachment is defined in source HTML. - Launch WeasyPrint in a sandbox that prevents access to the filesystem and the network.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-35jj-wx47-4w8r[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-28184[ADVISORY]
- https://github.com/Kozea/WeasyPrint/commit/734ee8e2dc84ff3090682f3abff056d0907c8598[WEB]
- https://github.com/Kozea/WeasyPrint[PACKAGE]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLQZMOEDY72TS43HDXOBVID2VYCTWIH6[WEB]
- https://pypi.org/project/weasyprint[PACKAGE]
- https://github.com/advisories/GHSA-35jj-wx47-4w8r[ADVISORY]