CVE-2025-64712Disclosure(unstructured / unstructured)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch unstructured unstructured systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. Prior to version 0.18.18, a path traversal vulnerability in the partition_msg function allows an attacker to write or overwrite arbitrary files on the filesystem when processing malicious MSG files with attachments. This issue has been patched in version 0.18.18.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unstructured

Threat summary

  • Patch or workaround signal is available
  • 27 mentions across 12 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 21 signals
  • Disclosure: 15 classified signals
  • General: 5 classified signals
  • Peaked 7d ago at 8 mentions (2026-02-13); latest day: 1
  • 27 total mentions across 12 days

Affected systems

Products
unstructured

Deep dive

Activity timeline27 mentions / 12d
02468Mentions · 2026-02-04: 4Mentions · 2026-02-06: 1Mentions · 2026-02-09: 3Mentions · 2026-02-12: 3Mentions · 2026-02-13: 8Mentions · 2026-02-14: 1Mentions · 2026-02-15: 2Mentions · 2026-02-16: 1Mentions · 2026-02-17: 1Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Mentions · 2026-04-09: 1Patch / Workaround · 2026-02-13: 3Patch / Workaround · 2026-02-14: 1Patch / Workaround · 2026-02-15: 1Patch / Workaround · 2026-02-17: 1Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-04: 3Technical Details · 2026-02-12: 3Technical Details · 2026-02-13: 8Technical Details · 2026-02-14: 1Technical Details · 2026-02-15: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 1Technical Details · 2026-04-09: 102-0402-0602-0902-1202-1302-1402-1502-1602-1702-1902-2004-09
Signal classification3 categories
Disclosure
1555.6%
Patch
725.9%
General
518.5%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-02-044
Disclosure3General1
2026-02-061
General1
2026-02-093
Disclosure2General1
2026-02-123
Disclosure3
2026-02-138
Disclosure5Patch3
2026-02-141
Patch1
2026-02-152
General1Patch1
2026-02-161
Disclosure1
2026-02-171
Patch1
2026-02-191
General1
2026-02-201
Patch1
2026-04-091
Disclosure1
Full discourse20 posts
  • /r/netsec@_r_netsec
    Disclosure

    Critical RCE Vulnerability in http://Unstructured.io (CVE-2025–64712) - CVSS 9.8 https://www.cyera.com/research-labs/inside-destructured---critical-vulnerability-in-unstructured-io-cve-2025-64712

    Post summary

    The post announces a critical RCE vulnerability (CVE‑2025‑64712) in Unstructured.io, noting a CVSS score of 9.8, but it lacks any PoC, exploit code, patch, or active exploitation details.

    13054773
    32.7K followersView on X
  • SC Media@SCMagazine
    Patch

    .@cyera_io reports that Unstructured hit with critical path traversal (CVE-2025-64712): crafted .msg attachment filenames can enable arbitrary file write → potential RCE. Patch to v0.18.18 now. #cybersecurity #CISO #infosec #ITsecurity https://bit.ly/4aPmG0o

    Post summary

    The post discloses a critical path traversal vulnerability (CVE‑2025‑64712) in Unstructured that could lead to RCE via crafted .msg filenames, and announces that a patch (v0.18.18) is now available.

    11040522
    119.3K followersView on X
  • Dor Attias@dorattias
    Disclosure

    🚨 Critical vuln (CVE-2025-64712, CVSS 9.8) in http://unstructured.io - used by 87% of Fortune 1000 Arbitrary File Write via Path Traversal allows threat actors to execute code & takeover machines running the library. Full details: https://www.cyera.com/research-labs/inside-destructured---critical-vulnerability-in-unstructured-io-cve-2025-64712 @cyera_io Research

    Post summary

    The post announces a critical vulnerability (CVE‑2025‑64712) in unstructured.io with a high CVSS score, detailing a path‑traversal based arbitrary file write that could allow code execution; no PoC, exploit code, or active exploitation claims are provided.

    10021190
    67 followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    Critical RCE Vulnerability in http://Unstructured.io (CVE-2025–64712) - CVSS 9.8 https://www.cyera.com/research-labs/inside-destructured---critical-vulnerability-in-unstructured-io-cve-2025-64712

    Post summary

    A critical remote code execution vulnerability (CVE-2025‑64712) has been identified in Unstructured.io, rated CVSS 9.8, with an associated research link provided.

    01001585
    33.0K followersView on X
  • Ayush Rijith@AyushRijith
    General

    @_ar9av @prismor_dev the critical ones include CVE-2025-29927 , CVE-2025-7783 , CVE-2023-50447 , CVE-2025-43859, CVE-2023-39662 , CVE-2024-23751 , CVE-2025-1793 this one has a sql injection vulnerability , CVE-2023-39631 , CVE-2024-3829 , CVE-2023-6730 , CVE-2025-64712 and more..

    Post summary

    The message lists several critical CVEs, noting that CVE-2025-1793 contains a SQL injection flaw, but offers no additional details such as PoC, exploitation status, or patches.

    0002079
    6 followersView on X
  • GBHackers on Security@gbhackers_news
    Disclosure

    CVE-2025-64712 in Unstructured io Puts Amazon, Google, and Tech Giants at Risk of Remote Code Execution | Source: https://gbhackers.com/cve-2025-64712-in-unstructured-io/ #CybersecurityNews https://t.co/YfqWW7QNVO

    Post summary

    The tweet announces CVE‑2025‑64712, a remote code execution flaw that could affect major cloud providers, but it offers no exploit code or patch details.

    00020239
    10.6K followersView on X
  • Cyera@cyera_io
    Disclosure

    @cyera_io Research Labs’ @dorattias just disclosed DESTRUCTURED (CVE-2025-64712): a CVSS 9.8 arbitrary file write vulnerability in Unstructured. io, the ETL engine behind a large portion of enterprise AI pipelines. In plain terms: ➡️ Write any file, anywhere on the host ➡️ Overwrite SSH keys, cron jobs, startup scripts ➡️ High likelihood of remote code execution ➡️ Supply chain blast radius across AI frameworks

    Post summary

    The tweet announces the discovery of CVE-2025-64712, a high-severity arbitrary file write vulnerability in Unstructured.io, highlighting its potential impact without mentioning a PoC, exploit, or mitigation.

    10010118
    715 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    LLM データ前処理ライブラリ「unstructured」に深刻な脆弱性(CVE-2025-64712) https://rocket-boys.co.jp/security-measures-lab/critical-vulnerability-found-in-llm-data-preprocessing-library-unstructured-cve-2025-64712/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The text announces the discovery of a severe vulnerability (CVE‑2025‑64712) in the LLM data‑preprocessing library "unstructured" and links to a security lab article for more information.

    00020155
    318 followersView on X
  • iototsecnews@iototsecnews
    Patch

    http://Unstructured.io の脆弱性 CVE-2025-64712:AI 対応のパイプラインに RCE の可能性 https://iototsecnews.jp/2026/02/13/cve-2025-64712-in-unstructured-io-puts-amazon-google-and-tech-giants-at-risk-of-remote-code-execution/ AI で読み取る情報の下準備を行う Unstructured のETL ライブラリにおいて、サーバの完全な制御を奪われる、きわめて深刻な脆弱性が発見されました。この問題の原因は、Microsoft Outlook のメッセージファイル “.msg” を処理する際に、添付ファイルのオリジナル・ファイル名を適切に検証せずに、一時ディレクトリへ保存してしまう設計上の不備にあります。この欠陥を突く攻撃者が、ファイル名に “../../” などの階層を遡る特殊な文字を紛れ込ませると、システムは本来の一時フォルダを逸脱し、OS の重要な設定ファイルや実行プログラムを上書きしてしまいます。なお、一次ソースである Cyera アドバイザリには、”Make sure to update unstructured library to version 0.18.18 or newer in all of your applications and workloads” という記載がありました。ご利用のチームは、ご確認ください。 #CVE202564712 #Unstructuredio #Vulnerability

    Post summary

    Unstructured.io’s ETL library is susceptible to remote code execution through improperly validated .msg attachments; vendors are advised to upgrade to version 0.18.18 or newer to mitigate the risk.

    01000191
    484 followersView on X
  • SC Media@SCMagazine
    Patch

    .@cyera_io reports that Unstructured hit with critical path traversal (CVE-2025-64712): crafted .msg attachment filenames can enable arbitrary file write → potential RCE. Patch to v0.18.18 now. #cybersecurity #CISO #infosec #ITsecurity https://bit.ly/4aPmG0o

    Post summary

    The tweet reports a path traversal vulnerability (CVE‑2025‑64712) in Unstructured that can allow arbitrary file writes and potential RCE, and notes that version 0.18.18 contains the patch.

    01000320
    119.3K followersView on X
  • SC Media@SCMagazine
    Patch

    .@cyera_io reports that Unstructured hit with critical path traversal (CVE-2025-64712): crafted .msg attachment filenames can enable arbitrary file write → potential RCE. Patch to v0.18.18 now. #cybersecurity #CISO #infosec #ITsecurity https://bit.ly/4aPmG0o

    Post summary

    The tweet announces CVE-2025-64712, a path‑traversal flaw enabling possible RCE, and informs that patch v0.18.18 is now available.

    00001363
    119.3K followersView on X
  • SC Media@SCMagazine
    Patch

    .@cyera_io reports that Unstructured hit with critical path traversal (CVE-2025-64712): crafted .msg attachment filenames can enable arbitrary file write → potential RCE. Patch to v0.18.18 now. #cybersecurity #CISO #infosec #ITsecurity https://bit.ly/4aPmG0o

    Post summary

    Unstructured software has a CVE‑2025‑64712 path traversal flaw that permits arbitrary file writes through crafted .msg attachments; the vendor has released patch v0.18.18.

    00010247
    119.3K followersView on X
  • transilienceai@transilienceai
    Disclosure

    @secharvesterx 🚨 CVE-2025-64712 is a critical path traversal vulnerability (CVSS 9.8) in the Unstructured library, an open-source tool for parsing and preprocessing various document types. #CyberSecurity #Vulnerability

    Post summary

    The post announces CVE-2025-64712 as a critical path traversal flaw in the Unstructured library, noting its CVSS score of 9.8.

    1000040
    315 followersView on X
  • transilienceai@transilienceai
    Disclosure

    🚨 **CVE-2025-64712** is a critical **path traversal vulnerability** in the **Unstructured library**, an open-source tool for parsing various document types. It has a **CVSS score of 9.8**, indicating high severity and potential for remote code execution (RCE). #CyberSecurity #Vulnerability

    Post summary

    A critical path traversal vulnerability (CVE-2025-64712) in the Unstructured library has been disclosed with a CVSS score of 9.8, potentially enabling remote code execution.

    1000048
    315 followersView on X
  • Security Harvester@secharvesterx
    Disclosure

    Critical RCE Vulnerability in http://Unstructured.io (CVE-2025–64712) - CVSS 9.8 https://www.cyera.com/research-labs/inside-destructured---critical-vulnerability-in-unstructured-io-cve-2025-64712 https://t.co/qQSBmwXq72

    Post summary

    The post announces a critical remote code execution vulnerability (CVE‑2025‑64712) in Unstructured.io with a CVSS score of 9.8, without mentioning exploitation, patches, or a PoC.

    1000095
    406 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Disclosure

    LLM データ前処理ライブラリ「unstructured」に深刻な脆弱性(CVE-2025-64712) https://rocket-boys.co.jp/security-measures-lab/critical-vulnerability-found-in-llm-data-preprocessing-library-unstructured-cve-2025-64712/

    Post summary

    The post announces a serious vulnerability (CVE-2025-64712) in the LLM data‑preprocessing library "unstructured" and directs readers to a security lab blog for details.

    0001069
    44 followersView on X
  • Soo Yoon | FailSafe Ecosystem@sooyoon_eth
    General

    LLM data preprocessing vulns are scary because everyone's using unstructured for data ingestion. CVE-2025-64712 = yet another reminder that the AI stack has way more attack surface than people realize. audit your dependencies pls

    Post summary

    The post highlights CVE-2025-64712 as another AI stack vulnerability, urging users to audit dependencies.

    0001083
    23.7K followersView on X
  • transilienceai@transilienceai
    Disclosure

    🚨 **CVE-2025-64712** is a critical path traversal vulnerability in the http://Unstructured.io library's `partition_msg` function. It allows attackers to write or overwrite arbitrary files on the filesystem when processing malicious MSG files with attachments, potentially leading to remote code execution. #CyberSecurity #Vulnerability

    Post summary

    CVE-2025-64712 is a path traversal flaw in Unstructured.io's `partition_msg` function that permits arbitrary file writes and potential remote code execution when processing malicious MSG files. No PoC, exploit, patch, or active exploitation information is provided.

    0000051
    313 followersView on X
  • Dr.Philippe Vynckier, CISSP - Influencer@PVynckier
    General

    CVE-2025-64712 in http://Unstructured.io Puts Amazon, Google, and Tech Giants at Risk of Remote Code Execution https://gbhackers.com/cve-2025-64712-in-unstructured-io/

    Post summary

    The text references CVE‑2025‑64712 in Unstructured.io but does not provide details on exploitation, mitigation, or technical specifics.

    0000082
    24.1K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical http://Unstructured.io flaw lets attackers write arbitrary files via malicious Outlook .MSG (CVE-2025-64712) A path traversal bug in the unstructured library’s `partition_msg` handling of .MSG attachments lets attackers write/overwrite arbitrary files when processing a crafted email, potentially escalating to full compromise (e.g., overwriting SSH authorized_keys); fixed in unstructured v0.18.18. 🎯 Target: Global/Enterprises (AI/ETL pipelines processing untrusted .MSG) #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://cyberpress.org/critical-cve-2025-64712-vulnerability/

    Post summary

    A path‑traversal flaw in Unstructured’s partition_msg allows attackers to write arbitrary files via crafted .MSG attachments; the issue is fixed in version 0.18.18, with no evidence of active exploitation or PoC.

    0000058
    191 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appunstructuredunstructured-python-

Explore more