github deeplook/svglib v2.3.0
svglib 2.3.0

3 hours ago

Security

  • External <image>/<use> references can no longer escape the document's own
    directory. xlink_href_target() joined the reference onto the source
    directory and only checked os.access(), so an absolute reference discarded
    that directory and .. climbed above it, letting an untrusted SVG name any
    file the process could read (CWE-22, GHSA-2p5c-8vcc-4rcw). Absolute
    references are now refused, and the new opt-in external_reference_root on
    svg2rlg()/SvgRenderer confines resolution to a trusted directory,
    propagated into nested external-SVG renderers. Relative references, including
    .., keep working by default.

  • The svg2pdf command line tool now sets external_reference_root to the
    input file's own directory, since a file converted from the command line is
    routinely one the user did not author. Pass -R/--external-root with a
    parent directory to allow shared assets, or / to allow any relative
    reference. Library callers are unaffected: the default stays None.

Don't miss a new svglib release

NewReleases is sending notifications on new releases.