pdfminer.six is vulnerable to Deserialization of Untrusted Data
86
High Risk
CMapDB._load_data() deserializes CMap data with pickle.loads() from a .pickle.gz path derived from the PDF's encoding name, and that path is not confined to the package cmap/ directory. A crafted PDF can point at an attacker-controlled pickle (including a Windows network path), so processing the document executes arbitrary Python code under the pdfminer process. The fix stops loading attacker-influenced pickle paths for CMap data.
You are affected if you are using a version that falls within the vulnerable range and process untrusted PDF files with pdfminer.
pdfminer.six is vulnerable to Deserialization of Untrusted Data in versions 20140915 - 20251229.
Upgrade the pdfminer.six and/or the pdfminer-six library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.