{"id":"CVE-2026-49452","summary":"WeasyPrint: CSS Injection via Presentational Hints","details":"WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CSS in weasyprint/css/__init__.py when presentational_hints=True. The background attribute is inserted into a background-image:url() declaration and parsed by tinycss2.parse_blocks_contents(), allowing untrusted HTML to inject additional CSS declarations. Applications that render untrusted HTML with presentational hints enabled can be affected by CSS injection and server-side requests through injected url() values. This issue is fixed in version 69.0.","aliases":["GHSA-jhhc-3hcp-qhm5","PYSEC-2026-3412"],"modified":"2026-08-21T03:30:38.388180152Z","published":"2026-08-18T17:59:36.144Z","related":["openSUSE-SU-2026:11249-1","openSUSE-SU-2026:21364-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49452.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-74"]},"references":[{"type":"WEB","url":"https://github.com/Kozea/WeasyPrint/releases/tag/v69.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49452.json"},{"type":"ADVISORY","url":"https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-jhhc-3hcp-qhm5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49452"},{"type":"FIX","url":"https://github.com/Kozea/WeasyPrint/commit/e158264e33fa399b29f415d30719c1d85a55df1d"},{"type":"FIX","url":"https://github.com/Kozea/WeasyPrint/pull/2773"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kozea/weasyprint","events":[{"introduced":"0"},{"fixed":"e158264e33fa399b29f415d30719c1d85a55df1d"},{"fixed":"32873118e8a70ceef87643775c247384d64798ea"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"69.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v68.1","v68.0","v67.0","v66.0","v65.0","v64.1","v64.0","v63.1","v63.0","v62.1","v62.0","v61.1","v61.0","v60.1","v60.0","v59.0","v58.1","v59.0b1","v58.0","v58.0b1","v57.1","v57.0","v57.0b1","v56.0b1","v55.0b1","v54.0","v54.0b1","v53.0","v53.0b2","v53.0b1","v51","v50","v49","v48","v47","v46","v45","v44","v43","v43rc2","v43rc1","v0.42","v0.41","v0.40","v0.39","v0.38","v0.37","v0.36","v0.35","v0.34","v0.33","v0.32","v0.31","v0.30","v0.29","v0.28","v0.27","v0.26","v0.25","v0.24","v0.20.1","v0.20","v0.19.1","v0.19","v0.18","v0.17.1","v0.17","v0.16","v0.15","v0.14","v0.13","v0.12","v0.11","v0.10","v0.9","v0.8","v0.7","v0.6","v0.5","v0.2","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49452.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}