CSS Injection Vulnerability in WeasyPrint by Kozea
CVE-2026-49452
6.5MEDIUM
What is CVE-2026-49452?
WeasyPrint, a tool for generating PDF documents, was found to have a security issue whereby unescaped HTML presentational-hint attribute values could lead to CSS injection vulnerabilities. Specifically, when presentational hints are enabled, malicious users could exploit this flaw to insert harmful CSS declarations into the background-image:url() parsing process via the TinyCSS2 library. This risk becomes prominent when applications render untrusted HTML content, potentially allowing for unauthorized CSS manipulations and server-side requests through crafted url() values. Users are encouraged to upgrade to version 69.0, where this vulnerability has been addressed.
Affected Version(s)
WeasyPrint < 69.0
