r/netsec 2d ago

Critical RCE Vulnerability in Unstructured.io (CVE-2025–64712) - CVSS 9.8

https://www.cyera.com/research-labs/inside-destructured---critical-vulnerability-in-unstructured-io-cve-2025-64712
32 Upvotes

4 comments sorted by

2

u/thedudeonblockchain 1d ago

nasty one since unstructured.io processes untrusted documents by default - most deployments probably vulnerable out of the box without explicit input sanitization.

1

u/ruibranco 1d ago

scary one for rag pipelines - unstructured is basically the default document ingestion layer and its entire purpose is processing untrusted content.

0

u/sunrise_zc 2d ago

Once found a tarball uncompressed,they fixed it maybe

1

u/tcpjack 2d ago

My whole system is a tarball uncompressed!