Source: weasyprint
Version: 69.0-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for weasyprint.

CVE-2026-55073[0]:
| WeasyPrint helps web developers to create PDF documents. Prior to
| 70.0, server-side applications that configure a restrictive
| url_fetcher and pass attacker-influenced values to HTML.write_pdf()
| can have the restriction bypassed through the xmp_metadata or
| stylesheets options. In weasyprint/pdf/init.py, xmp_metadata calls
| select_source() without the document url_fetcher, allowing an
| accessible local file to be read and embedded verbatim in the output
| PDF. In weasyprint/document.py, stylesheets constructs CSS() without
| the document url_fetcher, allowing local or internal resource
| loading and propagating the permissive fetcher through nested CSS
| imports and url() references. The stylesheets channel applies
| fetched resources but does not by itself disclose stylesheet
| comments verbatim. This issue is fixed in version 70.0.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-55073
    https://www.cve.org/CVERecord?id=CVE-2026-55073
[1] https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-jf6q-chmf-3h3v
[2] 
https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to