CVE-2026-49358
### Summary `AbstractGenerator::$temporaryFiles` is a public array, and `removeTemporaryFiles()` — invoked from `__destruct()` and from a registered shutdown function — calls `unlink()` on every entry without verifying that the path is contained within the temporary folder. Any code holding a reference to a generator instance can push an arbitrary path into the array and have it deleted on script shutdown. This mirrors the KnpLabs/snappy issue [GHSA-87qc-37cw-84h4](https://github.com/KnpLabs/snappy/security/advisories/GHSA-87qc-37cw-84h4), patched in snappy 1.7.2. ### Affected versions `pontedilana/php-weasyprint` versions `<= 2.5.1`. Patched in: `2.6.0`. ### Vulnerable code `src/AbstractGenerator.php`: ```php public array $temporaryFiles = []; // ... public function removeTemporaryFiles(): void { foreach ($this->temporaryFiles as $file) { $this->unlink($file); } } ``` No path-containment check: whatever path is present in `$temporaryFiles` at shutdown is unlinked. ### Proof of concept ```php <?php use Pontedilana\PhpWeasyPrint\Pdf; $pdf = new Pdf(); $pdf->temporaryFiles[] = '/var/www/html/.env'; // On shutdown, removeTemporaryFiles() deletes /var/www/html/.env. ``` ### Impact - Arbitrary file deletion bound to script shutdown, scoped to the privileges of the PHP process user. - Not directly exploitable on its own (the attacker already needs to influence the property in the same request). The risk is **amplification**: chained with a separate disclosure bug it enables leak-then-delete-to-cover-tracks, and any deserialization/property-oriented gadget that reaches this property becomes a generic file-delete primitive. CWE-73 (External Control of File Name or Path). ### Suggested fix Only delete files that actually live inside the temporary folder, comparing canonical (`realpath`) paths: ```php public function removeTemporaryFiles(): void { $temporaryFolderPath = \realpath($this->getTemporaryFolder()); if (false === $tempora
Properties
- summary
- PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles
- severity
- low
- epss_score
- 0.00149
- cvss_score
- 3
- ghsa_published
- 2026-06-26T22:10:51Z
- source_url
- https://github.com/advisories/GHSA-5g9f-cwwg-4p8g
- ghsa_updated
- 2026-06-26T22:10:53Z
- ghsa_id
- GHSA-5g9f-cwwg-4p8g
- cve_id
- CVE-2026-49358
- cvss_vector
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
- is_ghsa_only
- false
- epss_percentile
- 0.04632
Related Entities (5)
ENRICHED_BY (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph