Information Exposure Affecting unstructured package, versions [,0.16.20)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-UNSTRUCTURED-9055244
  • published2 Mar 2025
  • disclosed1 Mar 2025
  • creditUnknown

Introduced: 1 Mar 2025

New CVE NOT AVAILABLE CWE-200  (opens in a new tab)

How to fix?

Upgrade unstructured to version 0.16.20 or higher.

Overview

unstructured is an A library that prepares raw documents for downstream ML tasks.

Affected versions of this package are vulnerable to Information Exposure when the filetype supports an include functionality, it is possible to partition arbitrary local files.

This vulnerability specifically affects rst and org files. This is only exploitable if the include functionality is used to bring in content from files external to the partitioned file.

CVSS Scores

version 4.0
version 3.1