A security vulnerability has been discovered in Tryton (trytond) where weasyprint is not prevented from accessing local files when rendering HTML reports to PDF. The flaw carries a CVSS v3.0 base score of 4.9, with a network attack vector, low complexity, but requiring high privileges. There is no workaround — all affected users must upgrade trytond to versions 8.0.8, 7.8.14, or 7.0.55 or later depending on their series. Note that custom reports relying on local files may break after the upgrade and will need to be updated to use public HTTP URLs instead.
114 Impressions