WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if url_fetcher is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.
| Software | From | Fixed in |
|---|---|---|
weasyprint
|
61.0 | 61.2 |
| kozea / weasyprint | 61.0 | 61.2 |
| fedoraproject / fedora | 40 | 40.x |