Junglewise Threat Intelligence

CVE-2026-49358: pontedilana PhpWeasyPrint arbitrary file deletion in AbstractGenerator

CVE-2026-49358 · Severity: low · CVSS 3.1 · Published 2026-06-19

Technologies: pontedilana/php-weasyprint (Packagist), Pontedilana Php-Weasyprint. Vendors: Packagist, Pontedilana.

Executive brief

PhpWeasyPrint is a library used to generate PDF documents from web pages. A security flaw allows an attacker who can already influence the application's internal state to delete arbitrary files on the server when the script finishes running. This could be used to delete critical configuration files or cover the tracks of other malicious activity.

Technical details

The vulnerability exists in `AbstractGenerator.php` where the `$temporaryFiles` property is declared as a public array. The `removeTemporaryFiles()` method, which is triggered during object destruction or script shutdown, iterates through this array and calls `unlink()` on each entry without verifying that the files reside within the designated temporary directory. An attacker who can manipulate this public property—for example, through a separate deserialization vulnerability or a property-oriented programming (POP) chain—can specify arbitrary file paths to be deleted. The issue is fixed in version 2.6.0 by implementing canonical path checks using `realpath()` to ensure only files within the temporary folder are deleted.

Affected products

  • pontedilana php-weasyprint <= 2.5.1

Timeline

  • 2026-05-25: disclosed: Advisory published by endelwar
  • 2026-06-19: advisory: NVD published CVE-2026-49358
  • 2026-06-26: advisory: GitHub reviewed advisory published

References

Related threats