Open Redirect Affecting unstructured package, versions [,0.24.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.25% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Open Redirect vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-UNSTRUCTURED-19233386
  • published23 Aug 2026
  • disclosed20 Aug 2026
  • credithayato1121

Introduced: 20 Aug 2026

NewCVE-2026-71428  (opens in a new tab)
CWE-601  (opens in a new tab)

How to fix?

Upgrade unstructured to version 0.24.0 or higher.

Overview

unstructured is an A library that prepares raw documents for downstream ML tasks.

Affected versions of this package are vulnerable to Open Redirect via the url argument in the partition, partition_html, and partition_md functions. An attacker can access internal network resources or sensitive endpoints by supplying crafted URLs, potentially leading to disclosure of internal responses or triggering unintended actions on internal services.

CVSS Base Scores

version 4.0
version 3.1