Description
PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a document-controlled BaseFont name directly onto the user-supplied output directory without stripping path separators or dot-dot sequences. Attackers can supply a crafted PDF, EPUB, XPS, or FB2 file with a BaseFont name containing encoded path separators that decode to ../ sequences or absolute paths, causing arbitrary file writes outside the intended output directory without requiring authentication or elevated privileges.
Published: 2026-09-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Write
Action: Patch
AI Analysis

Impact

PyMuPDF versions up to and including 1.28.2 allow attackers to supply a crafted PDF, EPUB, XPS, or FB2 file containing a BaseFont name that decodes to path traversal sequences. The library constructs the output filename by naively concatenating the BaseFont name onto a user‑supplied directory, resulting in the ability to write or overwrite files outside the intended location. This flaw permits arbitrary creation or modification of files anywhere on the filesystem that the user process can write to, exposing confidentiality, integrity, and availability risks.

Affected Systems

The vulnerability affects the PyMuPDF library, specifically versions up to and including 1.28.2. Users employing PyMuPDF through the Python package manager or other distribution channels are at risk. No vendor list beyond PyMuPDF is affected.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity of impact. The EPSS score is below 1%, indicating a very low expected exploitation frequency at this time. The flaw does not require authentication or elevated privileges, lowering the barrier for exploitation. Because the vulnerability is not listed in the CISA KEV catalog, no known active exploitation efforts have been documented at this time. Attackers can exploit the weakness by providing a malicious document to any process that calls extract_objects() for font extraction, thereby writing files arbitrarily within the system’s file hierarchy.

Generated by OpenCVE AI on September 20, 2026 at 22:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PyMuPDF to a version after the fix in commit b2c8f3a.
  • If an upgrade is not possible, run PDF processing in an isolated environment that limits write permissions to critical directories.
  • Sanitize BaseFont names by removing path separators and dot‑dot sequences before constructing output paths.

Generated by OpenCVE AI on September 20, 2026 at 22:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a document-controlled BaseFont name directly onto the user-supplied output directory without stripping path separators or dot-dot sequences. Attackers can supply a crafted PDF, EPUB, XPS, or FB2 file with a BaseFont name containing encoded path separators that decode to ../ sequences or absolute paths, causing arbitrary file writes outside the intended output directory without requiring authentication or elevated privileges.
Title PyMuPDF 1.28.2 Path Traversal via extract_objects() Font Branch
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T19:11:56.736Z

Reserved: 2026-08-27T21:39:20.460Z

Link: CVE-2026-82035

cve-icon Vulnrichment

Updated: 2026-09-14T19:11:53.231Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T19:17:50.380

Modified: 2026-09-24T20:44:42.207

Link: CVE-2026-82035

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-14T18:38:34Z

Links: CVE-2026-82035 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:00:07Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')