CVE-2026-106443
Deferred Deferred - Pending Action

Remote Code Execution in WeasyPrint via PostScript Handling

Vulnerability report for CVE-2026-106443, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic image dispatcher without excluding EPS or PostScript formats. On hosts with Ghostscript installed, Pillow EpsImagePlugin invokes the interpreter for attacker-controlled PostScript, which can produce interpreter-permitted effects and can lead to remote code execution when the installed Ghostscript version has a usable sandbox bypass. Hosts without Ghostscript do not reach this rasterization path. This issue is fixed in version 70.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Kozea WeasyPrint < 70.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in WeasyPrint before version 70.0 allows an attacker to pass EPS or PostScript image formats through HTML, CSS, SVG, or data URIs. If Ghostscript is installed on the system, Pillow's image processing will invoke Ghostscript to interpret the PostScript code, which can execute arbitrary commands due to a sandbox bypass in Ghostscript. This can lead to remote code execution.

Detection Guidance

Check WeasyPrint version with 'weasyprint --version'. If version is below 70.0, the system is vulnerable. Verify Ghostscript installation with 'gs --version' or 'which gs'. Inspect logs for unexpected PostScript processing attempts.

Impact Analysis

If you use WeasyPrint to generate PDFs and have Ghostscript installed, an attacker could craft a malicious image file that, when processed, executes arbitrary code on your system. This could allow unauthorized access, data theft, or system compromise. Systems without Ghostscript are not affected.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially causing data breaches or loss of sensitive information. This may violate GDPR's data protection requirements or HIPAA's security rules, depending on the data processed. Compliance could be compromised if the system is exploited.

Mitigation Strategies

Upgrade WeasyPrint to version 70.0 or later immediately. If Ghostscript is installed and not required, uninstall it. If Ghostscript is needed, ensure it is updated to a version with a working sandbox bypass fix.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106443. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart