CVE-2026-3029
HIGHPyMuPDF 1.26.5 - Path Traversal and Arbitrary File Write
Title source: manualDescription
A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF version, 1.26.5.
Scores
CVSS v3
7.5
EPSS
0.0002
EPSS Percentile
5.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
Status
published
Products (2)
Artifex Software Inc. *PyMuPDF*/PyMuPDF
1.26.5 - 1.26.7
pypi/PyMuPDF
1.26.5 - 1.26.7PyPI
Published
Mar 19, 2026
Tracked Since
Mar 19, 2026