Disclosure summary
### Summary This was found during a pentest, funded by the NLNnet foundation, conducted by Stefan Vink from Radically Open Security and the only High issue found. WeasyPrint passes fetched image bytes directly to Pillow's generic format dispatcher without restricting the input format. When Ghostscript is installed on the host, Pillow's EpsImagePlugin invokes it to rasterize attacker-controlled EPS/PS input. Any content that can supply an image to WeasyPrint (an URL, CSS image value, SVG image reference, or data URI) can therefore drive untrusted PostScript into an external interpreter. On hosts running a Ghostscript version with a known -dSAFER bypass, this yields remote code execution. ### Details The image pipeline reads an external response and hands the raw bytes to Pillow's format-agnostic Image.open, with no allowlist of safe raster formats: with fetch(url_fetcher, url) as response: bytestring = response.read() mime_type = forced_mime_type or response.content_type ... pillow_image = Image.open(BytesIO(bytestring)) Pillow selects the handler from the byte signature. For EPS/PS input it selects PIL.EpsImagePlugin, which invokes Ghostscript to rasterize the input when a Ghostscr
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-r543-q48m-4c9j
Open original source · Updated Oct 07, 2026
WeasyPrint: EPS images reach the Ghostscript interpreter resulting in RCE
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | WeasyPrint | 70.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T14:05:49-04:00
MODIFIED 2026-10-07T14:05:51-04:00
INGESTED 2026-10-08T12:30:38-04:00