CVE-2025-64712
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. Prior to version 0.18.18, a path traversal vulnerability in the partition_msg function allows an attacker to write or overwrite arbitrary files on the filesystem when processing malicious MSG files with attachments. This issue has been patched in version 0.18.18.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.63%
- CWE
- CWE-22, CWE-73
- Published
- 2026-02-04
- Last modified
- 2026-03-12
Affected products
- Unstructured-IO unstructured
Weakness type
Related vulnerabilities
- CVE-2026-87984 — An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an...
- CVE-2026-87983 — An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an...
- CVE-2026-87727 — a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an...
- CVE-2026-19991 — UsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File Deletion
- CVE-2026-77807 — AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress <= 11.0.4 - Unauthenticated Arbitrary File Read via 'user[name]' Parameter
- CVE-2026-49836 — psd-tools: arbitrary file write via smart-object filename
- CVE-2026-80424 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-45767 — Suricata datasets: save to absolute filename can be bypassed when combined with load command