CVE-2025-64712

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. Prior to version 0.18.18, a path traversal vulnerability in the partition_msg function allows an attacker to write or overwrite arbitrary files on the filesystem when processing malicious MSG files with attachments. This issue has been patched in version 0.18.18.
Configurations

Configuration 1 (hide)

cpe:2.3:a:unstructured:unstructured:*:*:*:*:*:python:*:*

History

27 Feb 2026, 20:30

Type Values Removed Values Added
First Time Unstructured
Unstructured unstructured
References () https://github.com/Unstructured-IO/unstructured/commit/b01d35b2373fd087d2e15162b9c021663c97155d - () https://github.com/Unstructured-IO/unstructured/commit/b01d35b2373fd087d2e15162b9c021663c97155d - Patch
References () https://github.com/Unstructured-IO/unstructured/security/advisories/GHSA-gm8q-m8mv-jj5m - () https://github.com/Unstructured-IO/unstructured/security/advisories/GHSA-gm8q-m8mv-jj5m - Mitigation, Vendor Advisory
CPE cpe:2.3:a:unstructured:unstructured:*:*:*:*:*:python:*:*
Summary
  • (es) La librería 'unstructured' proporciona componentes de código abierto para la ingesta y el preprocesamiento de imágenes y documentos de texto, como PDF, HTML, documentos de Word y muchos más. Antes de la versión 0.18.18, una vulnerabilidad de salto de ruta en la función 'partition_msg' permite a un atacante escribir o sobrescribir archivos arbitrarios en el sistema de archivos al procesar archivos MSG maliciosos con archivos adjuntos. Este problema ha sido parcheado en la versión 0.18.18.

04 Feb 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-04 18:16

Updated : 2026-02-27 20:30


NVD link : CVE-2025-64712

Mitre link : CVE-2025-64712

CVE.ORG link : CVE-2025-64712


JSON object : View

Products Affected

unstructured

  • unstructured
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-73

External Control of File Name or Path