{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/pymupdf--1.28.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:artifex:pymupdf:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PyMuPDF (\u003c= 1.28.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal","software-library"],"_cs_type":"threat","_cs_vendors":["Artifex Software"],"content_html":"\u003cp\u003ePyMuPDF through version 1.28.2 is vulnerable to a path traversal flaw located in the font branch of the extract_objects() function within src/\u003cstrong\u003emain\u003c/strong\u003e.py. The vulnerability arises because the library fails to sanitize document-controlled 'BaseFont' names before joining them with a user-supplied output directory. An attacker can supply a malicious PDF, EPUB, XPS, or FB2 document containing a BaseFont name manipulated with encoded path separators or dot-dot sequences. When a victim or automated service processes this document using the vulnerable extract_objects() function, the library may resolve the path to a location outside the intended directory. This permits arbitrary file writes on the host system, which could be leveraged to overwrite critical configuration files, drop webshells, or perform other malicious operations depending on the environment where the library is deployed. This issue was addressed in commit b2c8f3a.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary file writes with the permissions of the user running the PyMuPDF processing script or application. This vulnerability poses a significant risk to document processing pipelines, web applications that accept user-submitted files for rendering or extraction, and local utilities that process untrusted documents. If exploited, an attacker could potentially achieve remote code execution by overwriting binaries or configuration files, leading to full system compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the PyMuPDF library to a version containing the fix for commit b2c8f3a (version 1.28.3 or later) immediately.\u003c/li\u003e\n\u003cli\u003eAudit applications using PyMuPDF to identify instances where the extract_objects() function is invoked on untrusted or user-supplied document files.\u003c/li\u003e\n\u003cli\u003eImplement strict filesystem sandboxing or containerization for services that process document files to limit the potential impact of arbitrary file write vulnerabilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T19:35:53Z","date_published":"2026-09-14T19:35:53Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pymupdf-path-traversal/","summary":"PyMuPDF versions through 1.28.2 contain a path traversal vulnerability in the extract_objects() function, allowing attackers to perform arbitrary file writes via crafted document font metadata.","title":"Path Traversal Vulnerability in PyMuPDF Font Processing","url":"https://feed.craftedsignal.io/briefs/2026-09-pymupdf-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - PyMuPDF (\u003c= 1.28.2)","version":"https://jsonfeed.org/version/1.1"}