PT-2026-91398 · Pypi · Pymupdf
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
PyMuPDF versions prior to 1.28.3
Description
A path traversal issue exists in the
extract objects() function within src/ main .py. The software constructs output filenames by joining a document-controlled BaseFont name to a user-supplied output directory without removing path separators or dot-dot sequences. An unauthenticated attacker can provide a specially crafted PDF, EPUB, XPS, or FB2 file containing a BaseFont name with encoded path separators that decode to ../ sequences or absolute paths, leading to arbitrary file writes outside the intended directory.Recommendations
Update PyMuPDF to version 1.28.3 or later.
As a temporary mitigation, avoid using the
extract objects() function to process untrusted files.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pymupdf