CVE-2026-82035

Source
https://cve.org/CVERecord?id=CVE-2026-82035
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82035.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82035
Downstream
Published
2026-09-14T18:38:34Z
Modified
2026-09-16T03:47:39Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
PyMuPDF 1.28.2 Path Traversal via extract_objects() Font Branch
Details

PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/main.py, where the output filename is constructed by joining a document-controlled BaseFont name directly onto the user-supplied output directory without stripping path separators or dot-dot sequences. Attackers can supply a crafted PDF, EPUB, XPS, or FB2 file with a BaseFont name containing encoded path separators that decode to ../ sequences or absolute paths, causing arbitrary file writes outside the intended output directory without requiring authentication or elevated privileges.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82035.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "1.8.2"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/pymupdf/pymupdf

Affected ranges

Type
GIT
Repo
https://github.com/pymupdf/pymupdf
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.28.2"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.12.4
1.13.10
1.13.11
1.13.12
1.13.13
1.13.14
1.13.15
1.13.16
1.13.17
1.13.18
1.13.19
1.13.20
1.13.3
1.13.4
1.13.5
1.13.7
1.13.8
1.13.9
1.14.0
1.14.1
1.14.10
1.14.11
1.14.12
1.14.13
1.14.14
1.14.15
1.14.16
1.14.17
1.14.18
1.14.19
1.14.20
1.14.3
1.14.5
1.14.6
1.14.7
1.14.8
1.14.9
1.16.0
1.16.1
1.16.10
1.16.11
1.16.12
1.16.13
1.16.14
1.16.16
1.16.17
1.16.18
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.17.2
1.17.3
1.17.4
1.17.5
1.17.6
1.17.7
1.18.0
1.18.1
1.18.10
1.18.11
1.18.13
1.18.14
1.18.15
1.18.16
1.18.17
1.18.18
1.18.19
1.18.2
1.18.3
1.18.4
1.18.5
1.18.6
1.18.7
1.18.8
1.18.9
1.19.0
1.19.1
1.19.2
1.19.3
1.19.4
1.19.5
1.19.6
1.20.0
1.20.0rc1
1.20.0rc2
1.20.1
1.20.2
1.21.0
1.21.0rc1
1.21.0rc2
1.21.1
1.21.1rc1
1.22.0
1.22.1
1.22.2
1.22.3
1.22.5
1.23.0
1.23.0rc1
1.23.0rc2_b
1.23.1
1.23.10
1.23.11
1.23.12
1.23.13
1.23.14
1.23.15
1.23.16
1.23.17
1.23.18
1.23.19
1.23.2
1.23.20
1.23.21
1.23.22
1.23.23
1.23.24
1.23.25
1.23.26
1.23.3
1.23.4
1.23.5
1.23.6
1.23.7
1.23.8
1.23.9
1.23.9rc1
1.23.9rc2
1.24.0
1.24.1
1.24.10
1.24.11
1.24.12
1.24.13
1.24.14
1.24.2
1.24.3
1.24.4
1.24.5
1.24.6
1.24.7
1.24.8
1.24.9
1.25.0
1.25.1
1.25.2
1.25.3
1.25.4
1.25.5
1.26.0
1.26.1
1.26.3
1.26.4
1.26.5
1.26.6
1.26.7
1.27.1
1.27.2
1.27.2.2
1.27.2.3
1.28.0
1.28.2
internal-rf2.*
internal-rf2.4.1
v1.*
v1.12.4
v1.12.5
v1.12.6
v1.2
v1.7
v1.8
v1.9
v1.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82035.json"