4 Million Downloads at Risk: Critical Unstructured Flaw (CVSS 9.8) Allows RCE
ID: bf1fd28d-9139-5e6e-b864-2ad3b84010f2
STIX ID: report--bf1fd28d-9139-5e6e-b864-2ad3b84010f2
Feed Name: securityonline.info
Threat Score
A critical path-traversal vulnerability (CVE-2025-64712, CVSS 9.8) in the unstructured library lets attackers craft .msg attachments with traversal filenames to write arbitrary files when attachment processing is enabled, potentially leading to RCE; versions up to 0.18.17 are affected, a fix is available in 0.18.18, and a temporary mitigation is to set process_attachments=False.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
