
Don't just take my word for it, verify. We scanned a trending public Github repository by @Microsoft at microsoft/markitdown and found 2 critical OSVs interlinked to 6 CVEs, among other findings: https://github.com/microsoft/markitdown Dependencies: Pillow>=9.0.0 -> CVE-2023-50447, CVE-2024-28219, CVE-2023-44271. mcp~=1.8.0 -> CVE-2025-53366, CVE-2025-66416, CVE-2025-53365. Per this post, the dependency still exist at > >markitdown-ocr/pyproject.toml >markitdown-mcp/pyproject.toml
Post summary
The post reports discovery of multiple CVEs linked to a GitHub repository, focusing on vulnerability disclosure without providing PoC, exploit, or mitigation details.
