WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.

Project Subscriptions

Vendors Products
Fedoraproject Subscribe
Weasyprint Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-0798 WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.
Github GHSA Github GHSA GHSA-35jj-wx47-4w8r WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 02 Dec 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Fedoraproject
Fedoraproject fedora
Kozea
Kozea weasyprint
CPEs cpe:2.3:a:kozea:weasyprint:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
Vendors & Products Fedoraproject
Fedoraproject fedora
Kozea
Kozea weasyprint

Thu, 13 Feb 2025 18:00:00 +0000

Type Values Removed Values Added
Description WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2. WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-13T17:47:28.192Z

Reserved: 2024-03-06T17:35:00.857Z

Link: CVE-2024-28184

cve-icon Vulnrichment

Updated: 2024-08-02T00:48:49.410Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-09T01:15:07.573

Modified: 2025-12-02T21:57:58.260

Link: CVE-2024-28184

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses