GHSA-p3rv-qj56-2fqxHighCVSS 7.5

Cross-site Scripting in Pyhtml2pdf

Published
February 20, 2024
Last Modified
June 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain

arbitrary local files. This is possible because the application does not

validate the HTML content entered by the user.

🎯 Affected products1

  • pip/pyhtml2pdf:<= 0.0.6

🔗 References (5)