weasyprint@61.1 vulnerabilities

The Awesome Document Factory

Direct Vulnerabilities

Known vulnerabilities in the weasyprint package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Files or Directories Accessible to External Parties

weasyprint is a The Awesome Document Factory

Affected versions of this package are vulnerable to Files or Directories Accessible to External Parties by attaching them during the PDF generation process. A user can attach content of arbitrary files and URLs to a generated PDF document, even if url_fetcher is configured to prevent access.

How to fix Files or Directories Accessible to External Parties?

Upgrade weasyprint to version 61.2 or higher.

[61.0,61.2)