Vulnerability CVE-2024-1647


Published: 2024-02-20

Description:
Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain

arbitrary local files. This is possible because the application does not

validate the HTML content entered by the user.



Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://pypi.org/project/pyhtml2pdf/
https://fluidattacks.com/advisories/oliver/

Copyright 2026, cxsecurity.com

 

Back to Top