Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-3029

Опубликовано: 19 мар. 2026
Источник: redhat
CVSS3: 8.2

Описание

A path traversal and arbitrary file write vulnerability exist in the embedded get function in 'main.py' in PyMuPDF version, 1.26.5.

A flaw was found in PyMuPDF. This vulnerability, involving path traversal, allows an attacker to write arbitrary files to unintended locations on the system. The flaw is present in the embedded get function within the _main_.py file. Successful exploitation could lead to system compromise or data corruption.

Меры по смягчению последствий

To mitigate this issue, ensure that applications utilizing PyMuPDF, especially those processing untrusted documents, are run within a sandboxed environment with strict limitations on file system write access. Additionally, validate and sanitize all input paths before they are processed by PyMuPDF's get function to prevent path traversal.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/disk-image-cuda-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2449054PyMuPDF: PyMuPDF: Arbitrary file write via path traversal vulnerability

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF version, 1.26.5.

CVSS3: 7.5
nvd
5 месяцев назад

A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF version, 1.26.5.

CVSS3: 7.5
debian
5 месяцев назад

A path traversal and arbitrary file write vulnerability exist in the e ...

suse-cvrf
2 месяца назад

Security update for python-PyMuPDF

github
5 месяцев назад

PyMuPDF has a path traversal in _main_.py

8.2 High

CVSS3