SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-55073

MEDIUM · CVSS 6.2 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

WeasyPrint versions prior to 70.0 are vulnerable to a bypass of configured restrictions in server-side applications, allowing attackers to manipulate inputs to the HTML.write_pdf() function. This can lead to unauthorized access to local files, which may be embedded in generated PDF documents, potentially exposing sensitive information. Organizations using WeasyPrint for PDF generation should prioritize upgrading to version 70.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55073
Severity
MEDIUM
CVSS
6.2
EPSS
N/A

Original NVD Description

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed through the xmp_metadata or stylesheets options. In weasyprint/pdf/init.py, xmp_metadata calls select_source() without the document url_fetcher, allowing an accessible local file to be read and embedded verbatim in the output PDF. In weasyprint/document.py, stylesheets constructs CSS() without the document url_fetcher, allowing local or internal resource loading and propagating the permissive fetcher through nested CSS imports and url() references. The stylesheets channel applies fetched resources but does not by itself disclose stylesheet comments verbatim. This issue is fixed in version 70.0.