Threat Advisory

WeasyPrint Flaw Lets Attackers Invoke Ghostscript RCE

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

CVE-2026-106443 with a CVSS score of 8.8 is a remote code execution vulnerability in WeasyPrint caused by improper validation of image formats during document rendering. The application passes untrusted image data to Pillow without restricting supported formats, allowing crafted EPS or PostScript content supplied through image URLs, CSS, SVG references or data URIs to invoke Ghostscript when it is installed. Successful exploitation may allow file manipulation or remote code execution depending on the Ghostscript version and the availability of known sandbox bypasses.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

CVE-2026-106443 with a CVSS score of 8.8 is a remote code execution vulnerability in WeasyPrint caused by improper validation of image formats during document rendering. The application passes untrusted image data to Pillow without restricting supported formats, allowing crafted EPS or PostScript content supplied through image URLs, CSS, SVG references or data URIs to invoke Ghostscript when it is installed. Successful exploitation may allow file manipulation or remote code execution depending on the Ghostscript version and the availability of known sandbox bypasses.[emaillocker id="1283"]

 

RECOMMENDATIONS:

  • We recommend you to update WeasyPrint to version 70.0 or later.

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-r543-q48m-4c9j

[/emaillocker]
crossmenu