DESTRUCTURED - Critical Vulnerability in Unstructured.io (CVE-2025–64712)
ID: 26ad957e-afe1-56a7-a605-fa11fd8b6212
STIX ID: report--26ad957e-afe1-56a7-a605-fa11fd8b6212
Feed Name: Cyera Research Labs
Threat Score
A critical path-traversal vulnerability (CVE-2025-64712, CVSS 9.8) in the Unstructured.io open-source library allows attackers to write arbitrary files (and likely achieve RCE) by crafting .msg attachments that overwrite filesystem paths; the issue affects a wide supply chain of AI/document-processing tools and has been patched in version 0.18.18.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
