CVE-2026-106443: Remote Code Execution in WeasyPrint via Unvalidated Pillow EPS Processing
Vulnerability ID: CVE-2026-106443
CVSS Score: 8.8
Published: 2026-10-07
A critical remote code execution vulnerability was identified in WeasyPrint prior to version 70.0. When compiling HTML containing a malicious Encapsulated PostScript (EPS) graphic on a host with Ghostscript installed, Pillow invokes Ghostscript to process the image, executing arbitrary PostScript commands.
TL;DR
WeasyPrint prior to 70.0 allows unauthenticated remote code execution via malicious EPS images if Ghostscript is installed on the hosting server.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-20
- Attack Vector: Network (AV:N/AC:L/PR:L/UI:N)
- CVSS Severity Score: 8.8
- EPSS Score: 0.00689 (51.27th Percentile)
- Exploit Status: PoC Available
- CISA KEV Status: Not Listed
Affected Systems
- WeasyPrint < 70.0
-
WeasyPrint: < 70.0 (Fixed in:
70.0)
Code Analysis
Commit: 39cd37c
Don't use Ghostscript to render possibly dangerous EPS files.
diff --git a/weasyprint/images.py b/weasyprint/images.py\n---\n+++ b/weasyprint/images.py\n@@ -22,6 +22,9 @@\n ImageFile.LOAD_TRUNCATED_IMAGES = True\n \n+# Don't use Ghostscript to render possibly dangerous EPS files.\n+EpsImagePlugin.gs_binary = False\n
Exploit Details
- GitHub Security Advisory: Official advisory containing research analysis and proof of concept.
Mitigation Strategies
- Upgrade WeasyPrint to version 70.0 or later.
- Uninstall Ghostscript from the host environment if not strictly needed.
- Enforce egress network filtering on the PDF rendering application.
- Disable the EPS interpreter programmatically in legacy applications.
Remediation Steps:
- Identify instances running WeasyPrint versions prior to 70.0.
- Update the project dependencies to require WeasyPrint >= 70.0.
- Rebuild the application base Docker images to remove Ghostscript packages.
- Confirm the fix by validating that attempts to process EPS assets throw handlable exceptions instead of executing external binaries.
References
- GitHub Security Advisory GHSA-r543-q48m-4c9j
- WeasyPrint Fix Commit
- WeasyPrint Release v70.0
- NVD CVE-2026-106443 Detail
- CVE.org Record for CVE-2026-106443
Read the full report for CVE-2026-106443 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)