Impact
The vulnerability enables privileged staff users who can create or edit report or label templates to trigger WeasyPrint to fetch arbitrary files from HTTP, HTTPS or local file URLs. Because the rendering path does not restrict URL fetching and the generated PDF is stored before further processing, an attacker can cause the server to read any accessible local file or internal HTTP response and embed its contents into a PDF attachment, revealing sensitive data such as application credentials.
Affected Systems
All InvenTree installations running a version earlier than 1.4.0 are affected.
Risk and Exploitability
The CVSS base score of 6.5 indicates medium severity. The EPSS score is not provided and the vulnerability is not listed in CISA’s KEV, suggesting no known widespread exploitation yet. Exploitation requires a user with privileged staff rights to author report or label templates and the ability to submit a crafted template that instructs WeasyPrint to download a file. Once the template is rendered, the server reads the file and includes its contents in a PDF attachment, potentially exposing credentials and other sensitive information.
OpenCVE Enrichment