
Don't just take my word for it, verify. We scanned a trending public Github repository by @Microsoft at microsoft/markitdown and found 2 critical OSVs interlinked to 6 CVEs, among other findings: https://github.com/microsoft/markitdown Dependencies: Pillow>=9.0.0 -> CVE-2023-50447, CVE-2024-28219, CVE-2023-44271. mcp~=1.8.0 -> CVE-2025-53366, CVE-2025-66416, CVE-2025-53365. Per this post, the dependency still exist at > >markitdown-ocr/pyproject.toml >markitdown-mcp/pyproject.toml
Post summary
The user scanned a Microsoft GitHub repo and identified six CVEs in its dependencies, but provided no details on exploits, patches, or technical specifics.
