Impact
PyMuPDF versions up to and including 1.28.2 allow attackers to supply a crafted PDF, EPUB, XPS, or FB2 file containing a BaseFont name that decodes to path traversal sequences. The library constructs the output filename by naively concatenating the BaseFont name onto a user‑supplied directory, resulting in the ability to write or overwrite files outside the intended location. This flaw permits arbitrary creation or modification of files anywhere on the filesystem that the user process can write to, exposing confidentiality, integrity, and availability risks.
Affected Systems
The vulnerability affects the PyMuPDF library, specifically versions up to and including 1.28.2. Users employing PyMuPDF through the Python package manager or other distribution channels are at risk. No vendor list beyond PyMuPDF is affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity of impact. The EPSS score is below 1%, indicating a very low expected exploitation frequency at this time. The flaw does not require authentication or elevated privileges, lowering the barrier for exploitation. Because the vulnerability is not listed in the CISA KEV catalog, no known active exploitation efforts have been documented at this time. Attackers can exploit the weakness by providing a malicious document to any process that calls extract_objects() for font extraction, thereby writing files arbitrarily within the system’s file hierarchy.
OpenCVE Enrichment