WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
Description
Published to the GitHub Advisory Database
Mar 8, 2024
Reviewed
Mar 8, 2024
Published by the National Vulnerability Database
Mar 9, 2024
Last updated
Apr 1, 2024
Impact
Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if
url_fetcher
is configured to prevent access to files and URLs.Patches
Fixed by 734ee8e that’s included in 61.2
Workarounds
References