PT-2026-107115 · Unknown+1 · Ghostscript+2
CVE-2026-106443
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WeasyPrint versions prior to 70.0
Description
The image-loading path in
weasyprint/images.py passes image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to the Pillow generic image dispatcher without excluding EPS or PostScript formats. On systems where Ghostscript is installed, the EpsImagePlugin in Pillow invokes the interpreter for attacker-controlled PostScript. This can lead to remote code execution if the installed Ghostscript version has a usable sandbox bypass. Systems without Ghostscript are not affected by this rasterization path.Recommendations
Update to version 70.0.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghostscript
Pillow
Weasyprint