logo

4 Million Downloads at Risk: Critical Unstructured Flaw (CVSS 9.8) Allows RCE

ID: bf1fd28d-9139-5e6e-b864-2ad3b84010f2

STIX ID: report--bf1fd28d-9139-5e6e-b864-2ad3b84010f2

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-02-06

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical path-traversal vulnerability (CVE-2025-64712, CVSS 9.8) in the unstructured library lets attackers craft .msg attachments with traversal filenames to write arbitrary files when attachment processing is enabled, potentially leading to RCE; versions up to 0.18.17 are affected, a fix is available in 0.18.18, and a temporary mitigation is to set process_attachments=False.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.