Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.Referenceshttps://pypi.org/project/pyhtml2pdf/https://fluidattacks.com/advisories/oliver/