Impact
The WeasyPrint PDF library includes a restrictive URL fetcher configuration that should limit network or file system access during PDF generation. However, prior to version 70.0, server‑side applications that set a restrictive url_fetcher and supply attacker‑controlled HTML.write_pdf() input can bypass those restrictions. In the XMP metadata handler, select_source() is called without the document’s url_fetcher, allowing the library to read any accessible local file and embed it verbatim in the output PDF. In the stylesheets processor, CSS() is constructed without the document url_fetcher, permitting local or internal resource loading and propagating a permissive fetcher through nested CSS imports and url() references. While the stylesheets channel applies fetched resources, it does not disclose comments verbatim. These behaviors result in a privacy breach, enabling a local file read and server‑side request forgery (SSRF) attack, classified under CWE‑918 and CWE‑1220. The flaw is resolved in WeasyPrint 70.0.
Affected Systems
The issue affects the WeasyPrint library from any version preceding 70.0, as distributed by Kozea. Applications that embed WeasyPrint (for example, Django or Flask projects using the HTML.write_pdf() method) are potentially vulnerable if they configure a restrictive URL fetcher and accept attacker‑controlled input for PDF generation. There are no additional vendor versions identified beyond Kozea’s WeasyPrint distribution.
Risk and Exploitability
The CVSS score of 6.2 defines the vulnerability as moderate severity. The EPSS score is now listed as less than 1 %, indicating a low but non‑zero probability of exploitation. The vulnerability is not currently in the CISA KEV catalog. Exploitation requires an attacker to influence the data fed to HTML.write_pdf(), which typically occurs through a web endpoint that generates PDFs from user‑supplied content. Once triggered, the attacker can read arbitrary local files or issue internal network requests via the library’s relaxed fetch logic. The attack vector is server‑side, posing a threat to confidentiality and integrity of server data but not directly enabling remote code execution.
OpenCVE Enrichment
Github GHSA