Impact
Interacting with WeasyPrint before version 70.0 allows an attacker to embed EPS or PostScript image data, which WeasyPrint passes directly to Pillow without filtering. Pillow’s EpsImagePlugin will invoke the Ghostscript interpreter on such data, enabling the execution of arbitrary PostScript code. If the Ghostscript binary contains a sandbox bypass, this results in remote code execution on the host where WeasyPrint runs. The weakness is a classic input delivering crafted image references via HTML, CSS, or SVG that refer to EPS content.
Affected Systems
The affected product is WeasyPrint, distributed by Kozea. All releases older than 70.0 are vulnerable. The flaw is only exploitable on systems where the Ghostscript interpreter is installed because Pillow will call it to rasterize EPS images. Hosts lacking Ghostscript are not impacted by the rasterization path.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. EPSS data is not available, and the vulnerability is not currently listed in the CISA KEV catalog, which suggests a lower current exploitation probability but does not eliminate risk. The likely attack vector is the delivery of malicious image data through a WeasyPrint processing request, which an attacker could embed in a trusted content pipeline. Exfiltration or lateral movement would follow once the attacker gains code execution on the host.
OpenCVE Enrichment