Intel

AIKIDO-2025-10810

unstructured is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 14, 2025

72

High Risk

This Affects:

PYTHONunstructured
0.14.5 - 0.18.15
Fixed in 0.18.18
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a path traversal issue in email MSG attachment filenames, where malicious filenames containing path traversal sequences could allow files to be written outside the intended directory during processing by partition_msg functions. An attacker can exploit this vulnerability by crafting an email with an attachment filename that includes .. sequences, which may lead to unauthorized file access or manipulation.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

unstructured is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.14.5 - 0.18.15.

How to fix this

Upgrade the unstructured library to the patch version.