CVE-2026-49286 | pontedilana php-weasyprint up to 2.5.x PHAR fileExists deserialization (GHSA-92rv-4j2h-8mjj)
A vulnerability classified as problematic has been found in pontedilana php-weasyprint up to 2.5.x. The affected element is the function fileExists of the component PHAR Handler. The manipulation leads to deserialization.
This vulnerability is referenced as CVE-2026-49286. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More