CVE-2025-64712 in Unstructured.io Puts Amazon, Google, and Tech Giants at Risk of Remote Code Execution
ID: 296fb655-e18f-5466-b2a6-decdd56e41d3
STIX ID: report--296fb655-e18f-5466-b2a6-decdd56e41d3
Feed Name: GBHackers
A critical path-traversal vulnerability (CVE-2025-64712, CVSS 9.8) in the Unstructured.io "unstructured" ETL library can allow attackers to craft .msg attachments with traversal filenames (e.g., "../../root/.ssh/authorized_keys") that cause arbitrary file writes and may lead to remote code execution. The report highlights the library's broad use in AI ingestion pipelines across enterprises, the high blast radius when run with broad filesystem access, and recommends mitigations including running processing in isolated containers/VMs, avoiding root, enforcing path normalization/basename checks, and applying filename allowlists.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
