unstructured is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
72
High Risk
Affected versions of this package are vulnerable to a path traversal issue in email MSG attachment filenames, where malicious filenames containing path traversal sequences could allow files to be written outside the intended directory during processing by partition_msg functions. An attacker can exploit this vulnerability by crafting an email with an attachment filename that includes .. sequences, which may lead to unauthorized file access or manipulation.
You are affected if you are using a version that falls within the vulnerable range.
unstructured is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.14.5 - 0.18.15.
Upgrade the unstructured library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant