Executive brief
WeasyPrint is a Python library that converts HTML/CSS to PDF documents. A vulnerability in versions 61.0 and 61.1 allows attackers with access to the application to attach arbitrary files and URLs to generated PDFs, bypassing security controls that were supposed to restrict file and URL access. This could lead to unintended disclosure of sensitive local files or external content embedded in PDFs.
Technical details
The vulnerability exists in WeasyPrint versions 61.0–61.1 and allows arbitrary file and URL attachment to PDF documents through HTML source, even when the url_fetcher parameter is configured to restrict such access. The vulnerability class is improper resource validation (CWE-829). An authenticated user or application that processes untrusted HTML can exploit this by embedding attachment directives in HTML that reference sensitive files or external URLs. The attack requires network access to the WeasyPrint application and the ability to influence the HTML source being converted. The vulnerability was fixed in version 61.2 (commit 734ee8e).
Affected products
- Kozea WeasyPrint 61.0, 61.1
Timeline
- 2024-03-08: disclosed: GHSA-35jj-wx47-4w8r published
- 2024-03-08: patched: Fixed in version 61.2 (commit 734ee8e)
- 2024-03-09: other: CVE-2024-28184 published