Releases: AdnanMuhib/python-pdfkit
Releases · AdnanMuhib/python-pdfkit
Release list
🔒 Fix CVE-2025-26240: Secure HTML Meta Tag Option Parsing
This release addresses the security vulnerability CVE-2025-26240 in python-pdfkit. Previously, parsing HTML meta tags with the pdfkit- prefix allowed the injection of arbitrary wkhtmltopdf options (such as --enable-local-file-access, --post-file, or --script), which could lead to Local File Inclusion (LFI) and Server-Side Request Forgery (SSRF) when rendering untrusted HTML strings.
To resolve this issue, we introduce a secure options allowlist approach that validates and filters meta options by default, while retaining full backward compatibility for trusted content through an override parameter.
🛠️ Changes Include
- 🔒 Security Allowlist (
pdfkit/security.py): Added an explicit allowlist of layout/formatting options (e.g.,page-size,orientation,margins) that are safe to parse. - 🛡️ Validation Engine (
pdfkit/pdfkit.py): Updated_find_options_in_metato filter parsed options against the allowlist and emit aRuntimeWarningwhen a dangerous option is blocked. - 🔑 API Enhancement (
pdfkit/api.py): Exposed the parameterallow_unsafe_meta_tags=Falseinfrom_stringto give developers a secure fallback to restore legacy behavior if rendering trusted content. - 🧪 Regression Tests (
tests/pdfkit-tests.py): AddedTestPDFKitSecurityto fully test default safe behavior, allowlist restrictions, parameter propagation, and warnings. - 📝 Documentation (
README.rst,HISTORY.rst): Documented the vulnerability fix, provided migration guidance, bumped package version, and documented version changes. - 🙈 Git Cleanliness (
.gitignore): Added.DS_Storeto git ignore rules to prevent tracking environment files.
🧪 Test Plan
Verified that all 50 unit and integration tests pass successfully:
$ cd tests && PATH="$(pwd)/bin:$PATH" python pdfkit-tests.py
..................................................
----------------------------------------------------------------------
Ran 50 tests in 0.472s
OK