{"apiVersion":"1.0","identifier":"CVE-2026-49452","description":"WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CSS in weasyprint/css/__init__.py when presentational_hints=True. The background attribute is inserted into a background-image:url() declaration and parsed by tinycss2.parse_blocks_contents(), allowing untrusted HTML to inject additional CSS declarations. Applications that render untrusted HTML with presentational hints enabled can be affected by CSS injection and server-side requests through injected url() values. This issue is fixed in version 69.0.","publishedAt":"2026-08-18T18:17:49","lastModifiedAt":"2026-08-19T16:17:15","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-49452","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","epssProbability":0.00273,"riskScore":0.67,"affectedProduct":"WeasyPrint","affectedVersions":"<69.0","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-49452","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-49452","en":"https://www.redsauce.net/en/cves/CVE-2026-49452","fr":"https://www.redsauce.net/fr/cves/CVE-2026-49452","pt":"https://www.redsauce.net/pt/cves/CVE-2026-49452","de":"https://www.redsauce.net/de/cves/CVE-2026-49452","sk":"https://www.redsauce.net/sk/cves/CVE-2026-49452","el":"https://www.redsauce.net/el/cves/CVE-2026-49452"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-49452"}}