Update dependency unstructured to v0.24.0 [SECURITY] #99
No reviewers
Labels
No labels
bug
dependencies
documentation
duplicate
enhancement
good first issue
help wanted
invalid
python
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
dawid/rag-agent!99
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/pypi-unstructured-vulnerability"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
==0.17.2→==0.24.0Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
CVE-2025-64712 / GHSA-gm8q-m8mv-jj5m
More information
Details
A Path Traversal vulnerability in the
partition_msgfunction allows an attacker to write or overwrite arbitrary files on the filesystem when processing malicious MSG files with attachments.Impact
An attacker can craft a malicious .msg file with attachment filenames containing path traversal sequences (e.g.,
../../../etc/cron.d/malicious). When processed withprocess_attachments=True, the library writes the attachment to anattacker-controlled path, potentially leading to:
Affected Functionality
The vulnerability affects the MSG file partitioning functionality when
process_attachments=Trueis enabled.Vulnerability Details
The library does not sanitize attachment filenames in MSG files before using them in file write operations, allowing directory
traversal sequences to escape the intended output directory.
Workarounds
Until patched, users can:
process_attachments=Falsewhen processing untrusted MSG filesSeverity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
unstructured: Server-Side Request Forgery in the URL-based partitioning
CVE-2026-71428 / GHSA-4mvj-m6j5-pmf7
More information
Details
Summary
Server-Side Request Forgery in
unstructured. Theurl=argument ofpartition(),partition_html(), andpartition_md()is fetched viarequests.get()with no host validation. The response body is returned asElementtext, so this is a full-read SSRF — attackers reach loopback admin APIs, internal HTTP services, and cloud metadata endpoints, and read the response.unstructuredis the de facto URL ingestion layer for LangChainUnstructuredURLLoader, LlamaIndexUnstructuredReader, Chainlit, and many agent frameworks — secure defaults must live in the library, not in every downstream caller.Details
Three sinks, all in
unstructured == 0.22.26(verified onmainat199f255):unstructured/partition/auto.py:303—file_and_type_from_url(), reached viapartition(url=…).unstructured/partition/html/partition.py:160—partition_html(url=…). Post-fetchContent-Typecheck runs after the request hits the target.unstructured/partition/md.py:96—partition_md(url=…). No timeout (SSRF + slow-loris DoS).None of
is_private,is_loopback,ipaddress,gethostbyname, orallow_redirectsappear in any of the three files. Three exploitation paths apply: direct private-IP target; redirect bypass (allow_redirects=Truedefault); DNS rebinding (TOCTOU, closeable only by socket-pinning). Affected since0.4.7(Feb 2023) — ~219 releases, no validation ever introduced.PoC
Local-only.
pip install unstructured==0.22.26 flask requests.internal_server.py:exploit.py— uses the public top-level API:In production the attacker substitutes
169.254.169.254,metadata.google.internal, or any internal address.Impact
Attacker capabilities:
metadata.google.internal), Azure IMDS, Oracle Cloud, DigitalOcean, and EC2 instances still configured for IMDSv1 (which remains widely deployed in older accounts and in services that do not enforce IMDSv2-only). EC2 instances configured as IMDSv2-only are not exposed to direct credential theft via this SSRF, since IMDSv2 requires aPUTfor token acquisition; the SSRF still reaches the endpoint for reconnaissance and surface-mapping.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
Unstructured-IO/unstructured (unstructured)
v0.24.0Compare Source
Enhancements
partition,partition_html, andpartition_mdnow routeurl=fetches through a single shared helper (unstructured/safe_http.py) instead of ad-hocrequests.getcalls. The helper applies anhttp/httpsscheme allowlist, a hostname denylist with IDNA normalization, address validation performed at connect time, manual redirect handling with per-hop re-validation (dropping credential material on cross-origin hops), refusal of proxied requests, and a default(connect, read)timeout. Behavior change: fetches that resolve to non-routable, loopback, or link-local addresses are now rejected by default. SetUNSTRUCTURED_ALLOW_PRIVATE_URL=1(or passallow_private=True) to opt out for controlled local usage.v0.23.1Compare Source
Enhancements
fastandhi_resstrategies and emitted as elements alongside the content-stream text.Fixes
any(extracted_to_keep), which evaluatedFalsewhen the only kept extracted region was at index 0. On single-region pages (e.g. a PDF whose only text is one filled form field) this left a duplicate element; the guard now checks the array size.v0.23.0Compare Source
Enhancements
enrichment_originsmetadata field for per-attribute model provenance:ElementMetadatagains a serializedenrichment_originsfield mapping a written attribute name (e.g.text,text_as_html,embeddings) to a list of records{"type", "provider", "model"}, in application order. Enrichment producers stamp which model wrote (or contributed to) each attribute; authoring enrichments overwrite the list while additive ones append, preserving the prior author. A newConsolidationStrategy.DICT_LIST_UNIQUEmerges these dicts across elements during chunking (union keys, concatenate then dedupe records, preserving first-seen order).v0.22.32Compare Source
Fixes
get_text(e.g.LTTextBox), andextract_text_objectsonly collectedLTTextLine. Text held as looseLTChars inside anLTFigure- for example text drawn into a figure/XObject overlay rather than the main content stream - was dropped from the output. hi_res now groups such loose characters into text lines, inserting spaces on wide inter-character gaps and skipping hidden (render mode 3) and rotated characters.v0.22.31Compare Source
Enhancements
isolate_tableschunking option toisolate_table: the option added in 0.22.30 has been renamed for naming consistency. Callers passingisolate_tables=must update toisolate_table=.v0.22.30Compare Source
Enhancements
isolate_tablesto basic/title chunking options. Defaults toTrue(the post-#4307 behavior:Table/TableChunkelements always staged alone). Set toFalseto allow tables to share pre-chunks with adjacent non-table elements and be combined byPreChunkCombiner.v0.22.29Compare Source
Fixes
spacylimit: add a guard against callingspacytokenizer with very long text. Now long texts are truncated to fit under the character limit.v0.22.28Compare Source
Fixes
HtmlTablecompactification previously cleared every element's.tail, silently dropping real text between inline children. Pure-whitespace tails are still removed, but tails carrying content are now kept with internal whitespace collapsed.v0.22.27Compare Source
Fixes
is_ndjson_processablepreviously returnedTruefor any text starting with{, so.jsonand.ipynbfiles containing a single multi-line JSON object (e.g. Jupyter notebooks) were routed topartition_ndjson, which then crashed in itssplitlines()-based parser.v0.22.26Compare Source
Enhancements
table_extraction_methodfield toElementMetadatato track which algorithm produced a table (grid, tatr, vlm). Propagated fromLayoutElementduring PDF partitioning.v0.22.23Compare Source
Fixes
colspan/rowspanin first table chunk headers:HtmlTablecompactification no longer stripscolspanandrowspanattributes from table cells. Previously, the firstTableChunklost merged-cell structural information while continuation chunks retained it (via the source-HTML path used for repeated headers), yielding inconsistent header layout across a split table.v0.22.22Compare Source
Security
uv sync, the Dockerfile now substitutes all PyPI opencv-python variants with a source-builtopencv-contrib-python-headlesswheel compiled withWITH_FFMPEG=OFF, eliminating 14 bundled ffmpeg CVEs. The contrib-headless variant is a strict superset of the cv2 API (core + contrib modules, no GUI) so a single wheel replacesopencv-python,opencv-python-headless, andopencv-contrib-python.v0.22.21Compare Source
Enhancements
skip_table_chunkingto basic/title chunking options. WhenTrue,Tableelements are passed through unchanged without being split intoTableChunkelements, regardless of their size. Defaults toFalseto preserve existing behavior.v0.22.20Compare Source
Enhancements
detect_verticalfield toPDFMinerConfigand auto-enable it when rendered pages have/Rotatemetadata, so pdfminer groups rotated text into proper words instead of per-character regionsv0.22.18Compare Source
Fixes
ingest-test-fixtures-update-prCI job also update the markdown versions of the fixtures.Enhancements
data-page-numberattributes from ancestor elements and includes the page number in element metadata, consistent with the v2 parser behavior.v0.22.16Compare Source
Enhancements
element_to_md/elements_to_md): New keyword-onlyformula_markdown_style("auto","display_math","plain"; default"auto"). In"auto", display math ($$ ... $$) is used only when the text looks like notation (heuristic score) and contains no$/$$(avoids breaking Markdown and noisy OCR captions)."display_math"wraps whenever safe (still falls back to plain if$would corrupt fences)."plain"emits text only. Optionalnormalize_formula(defaultTrue) maps common Unicode operators to LaTeX-like tokens;normalize_formulastays before keyword-only options so positionalencoding/no_group_by_pagecallers are unchanged. Unicode√is never mapped to\\sqrt{}. Module constants:FORMULA_MARKDOWN_AUTO,FORMULA_MARKDOWN_DISPLAY_MATH,FORMULA_MARKDOWN_PLAIN.v0.22.12Compare Source
Fixes
v0.22.10Compare Source
Enhancements
repeat_table_headersto basic/title chunking options and table chunking internals so leading header rows are detected once and carried forward when large tables spill across multiple chunks.v0.22.6Compare Source
Fixes
v0.21.5Compare Source
Fixes
pdfminer.sixto>=20251230v0.21.2Compare Source
Fixes
en-core-web-smdirect URL dependency inpyproject.tomlwith theinstallerlibrary. The spaCy model is now downloaded and installed on first use with hash verification, removing the need for[tool.uv.sources]and making the install more portable.v0.21.1Compare Source
v0.21.0Compare Source
Fixes
zipfile.extractall()without path validation, enabling RCE via malicious packages (CVSS 10.0, no patch available). spaCy models install as pip packages, eliminating the vulnerable downloader entirely.v0.20.8Compare Source
Fixes
wraptso it is compatible withopentelemetry-instrumentation-httpxv0.20.6Compare Source
Fixes
v0.20.2Compare Source
Enhancements
release.ymlGitHub Actions workflow triggers on GitHub release, builds the package withuv build, publishes to PyPI viapypa/gh-action-pypi-publish, and uploads to Azure Artifacts viatwineuv sync --frozenwithuv sync --lockedacross all CI workflows, Dockerfile, and Makefile to fail fast on stale lockfiles--no-syncto alluv runanduv buildcommands that follow a prioruv syncstep to prevent implicit re-syncingv0.18.32Compare Source
Enhancements
pdfiumcalls behind a thread lockv0.18.31Compare Source
Enhancements
max_tokens,new_after_n_tokens, andtokenizerparameters tochunk_by_title()andchunk_elements()for chunking by token count instead of character count. Uses tiktoken for token counting. Install withpip install "unstructured[chunking-tokens]". (fixes #4127)Fixes
Bumped dependencies to address the following CVEs:
glibc & related (glibc, glibc-locale-posix, ld-linux, libcrypt1, posix-libc-utils, posix-libc-utils-bin): CVE-2026-0915, CVE-2026-0861, GHSA-5pf6-63v3-88hw, GHSA-xp56-6525-9chf
pyasn1: GHSA-63vm-454h-vhhq
py3-setuptools (Python 3.12/3.13): GHSA-58pv-8j8x-9vj2
ffmpeg (via OpenCV): CVE-2025-9951, CVE-2025-1594, CVE-2023-6604, CVE-2023-49502, CVE-2023-6602, CVE-2023-6605, CVE-2025-0518, CVE-2023-6601, CVE-2025-22919, CVE-2023-50010, CVE-2023-50008, CVE-2024-31582, CVE-2025-59729, CVE-2025-59730, CVE-2023-50007
ALLOW_PANDOC_NO_SANDBOX=trueenv var is set (fixes #3997)coordinates=Truecausing TypeError in hi_res PDF processing: Filter outcoordinatesandcoordinate_systemfrom kwargs before passing toadd_element_metadata()to prevent conflict with explicit parameters (fixes #4126)<pre>elements now generateCodeSnippetelements instead ofText, and chunking preserves internal whitespace for code snippets. (fixes #4095)v0.18.27Compare Source
Fixes
zoom_image(codeflash)Enhancement
sentence_count(codeflash)_PartitionerLoader._load_partitioner(codeflash)detect_languages(codeflash)contains_verb(codeflash)get_bbox_thickness(codeflash)2026010to fix ~15-18% performance regression from eager f-string evaluationv0.18.26Compare Source
Fixes
deltalake<1.3.0to fix ARM64 Docker builds (1.3.0 missing Linux ARM64 wheels)v0.18.24Compare Source
Enhancement
OCRAgentTesseract.extract_word_from_hocr(codeflash)Fixes
v0.18.21Compare Source
Enhancement
Features
Fixes
unstructured-inferenceto 1.1.2 to address CVEsv0.18.20Compare Source
Enhancement
Features
Fixes
v0.18.18Compare Source
Fixes
partition_msgfunctionsv0.18.15Compare Source
Enhancements
Features
Fixes
v0.18.14Compare Source
Enhancements
check_for_nltk_packageby 111% (codeflash)under_non_alpha_ratioby 76% (codeflash)Features
Fixes
v0.18.13Compare Source
Enhancements
Features
Fixes
partition_emailfunction is now more robust to non-standard date formats, including ISO-8601 dates with "Z" suffixes. This preventsValueErrorexceptions when partitioning emails with these date formats.v0.18.11Compare Source
Enhancements
charset-normalizerlibrary for encoding detection Previously we had bothchardetandcharset-normalizeras dependencies. We are droppingchardetand only usingcharset-normalizer.Features
<input>mapping in HTML transformations Bare<input>elements are now classified by theirtypeattribute (checkbox → Checkbox, radio → RadioButton, others → FormFieldValue).Fixes
v0.18.9Compare Source
Enhancements
Features
Fixes
v0.18.7Compare Source
Enhancements
text_as_htmlfor Table element now keeps bothinputandimgtag'sclassattribute Previously in partition HTML any tag inside a table is stripped of itsclassattribute. Now this attribute is preserved for bothinputandimgtag in the table element'smetadata.text_as_html.Features
Fixes
v0.18.6Compare Source
Enhancements
Features
Fixes
TableChunkfor the string value of the fieldtypewhen serializing elements of typeTableChunk, rather than using the valueTable.v0.18.5Compare Source
Enhancements
text_as_htmlfor Table element now keepsimgtag'sclassattribute Previously in partition HTML any tag inside a table is stripped of itsclassattribute. Now this attribute is preserved forimgtag in the table element'smetadata.text_as_html.Features
Fixes
v0.18.3Compare Source
Enhancements
Features
Fixes
v0.18.2Fixes
v0.18.1Enhancement
Features
Fixes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.