logo

CVE-2025-64712 in Unstructured.io Puts Amazon, Google, and Tech Giants at Risk of Remote Code Execution

ID: 296fb655-e18f-5466-b2a6-decdd56e41d3

STIX ID: report--296fb655-e18f-5466-b2a6-decdd56e41d3

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-02-13

Date Updated: 2026-04-22

Author: Divya

...
...

A critical path-traversal vulnerability (CVE-2025-64712, CVSS 9.8) in the Unstructured.io "unstructured" ETL library can allow attackers to craft .msg attachments with traversal filenames (e.g., "../../root/.ssh/authorized_keys") that cause arbitrary file writes and may lead to remote code execution. The report highlights the library's broad use in AI ingestion pipelines across enterprises, the high blast radius when run with broad filesystem access, and recommends mitigations including running processing in isolated containers/VMs, avoiding root, enforcing path normalization/basename checks, and applying filename allowlists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.