VYPR

Pymupdf

by Pymupdf

Source repositories

CVEs (1)

  • CVE-2026-82035HigSep 14, 2026
    risk 0.39cvss 7.1epss

    PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a document-controlled BaseFont name directly onto the user-supplied output…