CVE-2025-64512Patch(debian / debian_linux)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch debian debian_linux systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documents. Prior to version 20251107, pdfminer.six will execute arbitrary code from a malicious pickle file if provided with a malicious PDF file. The `CMapDB._load_data()` function in pdfminer.six uses `pickle.loads()` to deserialize pickle files. These pickle files are supposed to be part of the pdfminer.six distribution stored in the `cmap/` directory, but a malicious PDF can specify an alternative directory and filename as long as the filename ends in `.pickle.gz`. A malicious, zipped pickle file can then contain code which will automatically execute when the PDF is processed. Version 20251107 fixes the issue.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • pdfminer.six

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
debian_linuxpdfminer.six

1 version affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-22: 1PoC Mentioned / Linked · 2026-03-22: 1Patch / Workaround · 2026-03-22: 1Technical Details · 2026-03-22: 103-22
Signal classification1 categories
Patch
1100.0%
Referenced assets2 URLs
By indicator
Full discourse1 post
  • 3kidsdad@photometry
    Patch

    markitdown (microsoft/markitdown) 코드 보안 점검 ( Grok Review @grok ) **1차 분석 결과(위험)**와 일치합니다. 제가 GitHub 최신 상태(2026.3.22 기준, v0.1.5), NVD/CVE 데이터베이스, 이슈/PR, dependency pinning까지 직접 검증했습니다. ### 프로젝트 개요 - **Stars**: 91.4K (실제 확인) - **주요 기능**: PDF/DOCX/XLSX/PPTX/이미지/오디오/HTML/ZIP/YouTube 등 → Markdown 변환 - LLM 파이프라인(AutoGen, LangChain, MCP server) 최적화 - Optional extras: `[pdf]`, `[docx]`, `[all]` 등 ### 보안 점검 결과: **HIGH 위험** (Untrusted 파일 처리 시) **1. Critical Dependency CVE (이미 패치됨)** - **pdfminer.six CVE-2025-64512** (CVSS 8.4, RCE via malicious pickle in PDF) → v0.1.4에서 `20251107` → 후속 패치 `20251230`으로 pinning 완료. - **mammoth CVE-2025-11849** (CVSS 9.3, Directory Traversal in DOCX) → v0.1.4에서 `1.11.0`으로 업그레이드 완료. **2. 미패치 / Open 이슈 (여전히 존재)** - **XXE 취약점 (#1565)** — Open DOCX pre-processor (`_convert_omath_to_latex()`)에서 `ET.fromstring()`로 untrusted XML 직접 파싱. Billion Laughs + External Entity 공격 가능. defusedxml은 core에 있지만 해당 코드에서 미사용. PR 제출됐으나 미병합. - **Zip Bomb DoS (#1514)** — Open `ZipConverter`에서 `http://zipObj.read(name)`으로 전체 파일을 메모리에 한 번에 로드. 10MB Zip Bomb → 수 GB 메모리 폭발 가능. - **파일 크기/시간/메모리 제한 전무** → DoS 쉬움 (ZIP, PDF, 대용량 DOCX 등) **3. 추가 발견 위험** - **MCP Server SSRF (MCP fURI)**: AWS EC2 등 클라우드에서 metadata endpoint (`169.254.169.254`) credential 탈취 가능. - LLM OCR / Image Description 활성화 시: malicious 이미지 → prompt injection + 데이터 유출 위험. ### 안전 사용 조건 (필수 준수) - **0.1.5 이상 버전 필수** (dependency CVE 패치됨) - **내부/신뢰된 문서만 처리** (사용자 업로드 파일 절대 금지) - **LLM vision/OCR 기능 비활성화 권장** (`llm_client=None`) - **프로덕션 환경**: - Docker sandbox + resource limits (memory 512MB, timeout 30s, CPU limit) **반드시** - 앞단에 antivirus (ClamAV) + 파일 크기 제한 (최대 50MB) - MCP server는 internal network에서만 expose ### 결론 및 권고 1차 분석에서 “위험”이라고 한 것은 **정확**합니다. Dependency CVE는 최신 버전에서 해결됐지만, **markitdown 자체 코드의 XXE + Zip Bomb + No Limits** 때문에 **Untrusted 파일을 처리하는 순간 Critical** 수준입니다. **추천 대안** - 내부 문서만 쓴다면: v0.1.5 + Docker + LLM off → Low risk - 사용자 업로드 허용한다면: **직접 사용 금지** → Azure Document Intelligence나 안전한 대체 도구 (http://unstructured.io 등) 고려 - PR 머지 기다리기 (#1565, #1514) 또는 fork해서 limits + defusedxml 적용 상세 보고서(dependency pinning 스크린샷, 취약 코드 스니펫, PoC 예시, mitigation PR 제안 포함) 필요하시면 말씀해주세요. 바로 PDF로 정리해서 드리겠습니다! 추가 질문 있으신가요? (예: 특정 파일 타입별 위험도, Docker Compose 예시, 대체 라이브러리 비교 등)

    Post summary

    The post performs a security assessment of the markitdown project, highlights patched and open CVEs, provides technical details, and recommends mitigations—primarily focusing on patching and hardening.

    10010247
    2.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
Apppdfminerpdfminer.six---

Explore more