PT-2026-91398 · Pypi · Pymupdf

·

CVE-2026-82035

·

Published

2026-09-14

·

Updated

2026-09-22

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions PyMuPDF versions prior to 1.28.3
Description A path traversal issue exists in the extract objects() function within src/ main .py. The software constructs output filenames by joining a document-controlled BaseFont name to a user-supplied output directory without removing path separators or dot-dot sequences. An unauthenticated attacker can provide a specially crafted PDF, EPUB, XPS, or FB2 file containing a BaseFont name with encoded path separators that decode to ../ sequences or absolute paths, leading to arbitrary file writes outside the intended directory.
Recommendations Update PyMuPDF to version 1.28.3 or later. As a temporary mitigation, avoid using the extract objects() function to process untrusted files.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82035
OPENSUSE-SU-2026:11824-1
OPENSUSE-SU-2026:21912-1

Affected Products

Pymupdf