PT-2026-107115 · Unknown+1 · Ghostscript+2

CVE-2026-106443

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WeasyPrint versions prior to 70.0
Description The image-loading path in weasyprint/images.py passes image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to the Pillow generic image dispatcher without excluding EPS or PostScript formats. On systems where Ghostscript is installed, the EpsImagePlugin in Pillow invokes the interpreter for attacker-controlled PostScript. This can lead to remote code execution if the installed Ghostscript version has a usable sandbox bypass. Systems without Ghostscript are not affected by this rasterization path.
Recommendations Update to version 70.0.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106443
GHSA-R543-Q48M-4C9J

Affected Products

Ghostscript
Pillow
Weasyprint