Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if url_fetcher is configured to prevent access to files and URLs.
Fixed by 734ee8e that’s included in 61.2
{
"cwe_ids": [
"CWE-829"
],
"github_reviewed": true,
"github_reviewed_at": "2024-03-08T20:42:52Z",
"nvd_published_at": "2024-03-09T01:15:07Z",
"severity": "HIGH"
}