DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-106443: CVE-2026-106443: Remote Code Execution in WeasyPrint via Unvalidated Pillow EPS Processing

CVE-2026-106443: Remote Code Execution in WeasyPrint via Unvalidated Pillow EPS Processing

Vulnerability ID: CVE-2026-106443
CVSS Score: 8.8
Published: 2026-10-07

A critical remote code execution vulnerability was identified in WeasyPrint prior to version 70.0. When compiling HTML containing a malicious Encapsulated PostScript (EPS) graphic on a host with Ghostscript installed, Pillow invokes Ghostscript to process the image, executing arbitrary PostScript commands.

TL;DR

WeasyPrint prior to 70.0 allows unauthenticated remote code execution via malicious EPS images if Ghostscript is installed on the hosting server.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-20
  • Attack Vector: Network (AV:N/AC:L/PR:L/UI:N)
  • CVSS Severity Score: 8.8
  • EPSS Score: 0.00689 (51.27th Percentile)
  • Exploit Status: PoC Available
  • CISA KEV Status: Not Listed

Affected Systems

  • WeasyPrint < 70.0
  • WeasyPrint: < 70.0 (Fixed in: 70.0)

Code Analysis

Commit: 39cd37c

Don't use Ghostscript to render possibly dangerous EPS files.

diff --git a/weasyprint/images.py b/weasyprint/images.py\n---\n+++ b/weasyprint/images.py\n@@ -22,6 +22,9 @@\n ImageFile.LOAD_TRUNCATED_IMAGES = True\n \n+# Don't use Ghostscript to render possibly dangerous EPS files.\n+EpsImagePlugin.gs_binary = False\n
Enter fullscreen mode Exit fullscreen mode

Exploit Details

Mitigation Strategies

  • Upgrade WeasyPrint to version 70.0 or later.
  • Uninstall Ghostscript from the host environment if not strictly needed.
  • Enforce egress network filtering on the PDF rendering application.
  • Disable the EPS interpreter programmatically in legacy applications.

Remediation Steps:

  1. Identify instances running WeasyPrint versions prior to 70.0.
  2. Update the project dependencies to require WeasyPrint >= 70.0.
  3. Rebuild the application base Docker images to remove Ghostscript packages.
  4. Confirm the fix by validating that attempts to process EPS assets throw handlable exceptions instead of executing external binaries.

References


Read the full report for CVE-2026-106443 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)