Source: weasyprint Version: 69.0-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for weasyprint. CVE-2026-55073[0]: | WeasyPrint helps web developers to create PDF documents. Prior to | 70.0, server-side applications that configure a restrictive | url_fetcher and pass attacker-influenced values to HTML.write_pdf() | can have the restriction bypassed through the xmp_metadata or | stylesheets options. In weasyprint/pdf/init.py, xmp_metadata calls | select_source() without the document url_fetcher, allowing an | accessible local file to be read and embedded verbatim in the output | PDF. In weasyprint/document.py, stylesheets constructs CSS() without | the document url_fetcher, allowing local or internal resource | loading and propagating the permissive fetcher through nested CSS | imports and url() references. The stylesheets channel applies | fetched resources but does not by itself disclose stylesheet | comments verbatim. This issue is fixed in version 70.0. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-55073 https://www.cve.org/CVERecord?id=CVE-2026-55073 [1] https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-jf6q-chmf-3h3v [2] https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

