Intel

AIKIDO-2025-10078

unstructured is vulnerable to Exposure of Resource to Wrong Sphere

Exposure of Resource to Wrong Sphere Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 6, 2025

60

Medium Risk

This Affects:

pythonunstructured
0.6.12 - 0.16.19
Fixed in 0.16.20
Are you affected? Scan for Free

TL;DR

Affected versions of this package may expose resources to an unintended scope. Specifically, when processing files that support an include functionality, such as rst and org files, an attacker may be able to partition arbitrary local files, incorporating their contents into the processed output. This could lead to unauthorized disclosure of sensitive information or unintended file exposure.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

unstructured is vulnerable to Exposure of Resource to Wrong Sphere in versions 0.6.12 - 0.16.19.

How to fix this

Upgrade the unstructured library to the patch version.