logo

DESTRUCTURED - Critical Vulnerability in Unstructured.io (CVE-2025–64712)

ID: 26ad957e-afe1-56a7-a605-fa11fd8b6212

STIX ID: report--26ad957e-afe1-56a7-a605-fa11fd8b6212

Feed Name: Cyera Research Labs

Threat Score
90/100

Date Published: 2026-02-12

Date Updated: 2026-04-27

...
...

A critical path-traversal vulnerability (CVE-2025-64712, CVSS 9.8) in the Unstructured.io open-source library allows attackers to write arbitrary files (and likely achieve RCE) by crafting .msg attachments that overwrite filesystem paths; the issue affects a wide supply chain of AI/document-processing tools and has been patched in version 0.18.18.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.