CVE-2025-70559

Source
https://cve.org/CVERecord?id=CVE-2025-70559
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-70559.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-70559
Aliases
Downstream
Related
Published
2026-02-03T18:16:17.783Z
Modified
2026-04-10T05:35:29.778482Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to deserialize CMap cache files without validation. An attacker with the ability to place a malicious pickle file in a location accessible to the application can trigger arbitrary code execution or privilege escalation when the file is loaded by a trusted process. This is caused by an incomplete patch to CVE-2025-64512.

References

Affected packages

Git / github.com/pdfminer/pdfminer.six

Affected ranges

Type
GIT
Repo
https://github.com/pdfminer/pdfminer.six
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "pdfminer.six"
        },
        {
            "fixed": "20251230"
        }
    ]
}

Affected versions

Other
20160614
20170419
20170720
20181108
20191020
20191107
20191110
20200104
20200121
20200124
20200402
20200517
20200720
20200726
20201018
20211012
20220319
20220506
20220524
20221105
20240706
20250327
20250416
20250506
20251107
20251227
20251228
20251229

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-70559.json"