pymupdfpro@1.24.12 vulnerabilities

Commercial extensions for PyMuPDF; enables Office document handling, including doc, docx, hwp, hwpx, ppt, pptx, xls, xls, and others. Supports text and table extraction, document conversion and more.

  • latest version

    1.26.4

  • latest non vulnerable version

  • first published

    1 years ago

  • latest version published

    9 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the pymupdfpro package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Uncontrolled Recursion

    PyMuPDFPro is a Commercial extensions for PyMuPDF; enables Office document handling, including doc, docx, hwp, hwpx, ppt, pptx, xls, xls, and others. Supports text and table extraction, document conversion and more.

    Affected versions of this package are vulnerable to Uncontrolled Recursion when processing a crafted PDF file containing cyclic /Next references in the outline structure via the strip_outline function. An attacker can cause the application to enter an infinite recursion and crash by submitting a specially crafted PDF file.

    How to fix Uncontrolled Recursion?

    Upgrade PyMuPDFPro to version 1.26.1 or higher.

    [,1.26.1)