Description
WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic image dispatcher without excluding EPS or PostScript formats. On hosts with Ghostscript installed, Pillow EpsImagePlugin invokes the interpreter for attacker-controlled PostScript, which can produce interpreter-permitted effects and can lead to remote code execution when the installed Ghostscript version has a usable sandbox bypass. Hosts without Ghostscript do not reach this rasterization path. This issue is fixed in version 70.0.
Published: 2026-10-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Interacting with WeasyPrint before version 70.0 allows an attacker to embed EPS or PostScript image data, which WeasyPrint passes directly to Pillow without filtering. Pillow’s EpsImagePlugin will invoke the Ghostscript interpreter on such data, enabling the execution of arbitrary PostScript code. If the Ghostscript binary contains a sandbox bypass, this results in remote code execution on the host where WeasyPrint runs. The weakness is a classic input delivering crafted image references via HTML, CSS, or SVG that refer to EPS content.

Affected Systems

The affected product is WeasyPrint, distributed by Kozea. All releases older than 70.0 are vulnerable. The flaw is only exploitable on systems where the Ghostscript interpreter is installed because Pillow will call it to rasterize EPS images. Hosts lacking Ghostscript are not impacted by the rasterization path.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. EPSS data is not available, and the vulnerability is not currently listed in the CISA KEV catalog, which suggests a lower current exploitation probability but does not eliminate risk. The likely attack vector is the delivery of malicious image data through a WeasyPrint processing request, which an attacker could embed in a trusted content pipeline. Exfiltration or lateral movement would follow once the attacker gains code execution on the host.

Generated by OpenCVE AI on October 6, 2026 at 21:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WeasyPrint to version 70.0 or later, which removes EPS handling from Pillow’s dispatcher
  • If immediate upgrade is unavailable, remove Ghostscript from the host or switch to a hardened, sandboxed build of Ghostscript
  • Configure Pillow to reject EPS/PS formats or enforce strict file type validation on incoming image data
  • Monitor the system for attempts to load EPS content or for Ghostscript invocation events

Generated by OpenCVE AI on October 6, 2026 at 21:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic image dispatcher without excluding EPS or PostScript formats. On hosts with Ghostscript installed, Pillow EpsImagePlugin invokes the interpreter for attacker-controlled PostScript, which can produce interpreter-permitted effects and can lead to remote code execution when the installed Ghostscript version has a usable sandbox bypass. Hosts without Ghostscript do not reach this rasterization path. This issue is fixed in version 70.0.
Title WeasyPrint: EPS images reach the Ghostscript interpreter resulting in RCE
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T19:29:04.704Z

Reserved: 2026-10-06T16:49:40.590Z

Link: CVE-2026-106443

cve-icon Vulnrichment

Updated: 2026-10-06T19:27:05.520Z

cve-icon NVD

Status : Deferred

Published: 2026-10-06T19:18:13.327

Modified: 2026-10-06T20:17:26.023

Link: CVE-2026-106443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:30:08Z

Weaknesses
  • CWE-20

    Improper Input Validation