Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gm8q-m8mv-jj5m | Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 05 Feb 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Unstructured-io
Unstructured-io unstructured |
|
| Vendors & Products |
Unstructured-io
Unstructured-io unstructured |
Wed, 04 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. Prior to version 0.18.18, a path traversal vulnerability in the partition_msg function allows an attacker to write or overwrite arbitrary files on the filesystem when processing malicious MSG files with attachments. This issue has been patched in version 0.18.18. | |
| Title | Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write | |
| Weaknesses | CWE-22 CWE-73 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-04T19:24:12.411Z
Reserved: 2025-11-10T14:07:42.921Z
Link: CVE-2025-64712
Updated: 2026-02-04T19:24:07.200Z
Status : Received
Published: 2026-02-04T18:16:07.370
Modified: 2026-02-04T18:16:07.370
Link: CVE-2025-64712
No data.
OpenCVE Enrichment
Updated: 2026-02-05T11:39:37Z
Github GHSA