CVE-2025-64712

CRITICAL

Pypi Unstructured < 0.18.18 - Path Traversal

Title source: rule
STIX 2.1

Description

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. Prior to version 0.18.18, a path traversal vulnerability in the partition_msg function allows an attacker to write or overwrite arbitrary files on the filesystem when processing malicious MSG files with attachments. This issue has been patched in version 0.18.18.

Scores

CVSS v3 9.8
EPSS 0.0013
EPSS Percentile 32.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-73 CWE-22
Status published
Products (2)
pypi/unstructured 0 - 0.18.18PyPI
unstructured/unstructured < 0.18.18
Published Feb 04, 2026
Tracked Since Feb 18, 2026