CVE-2025-70559: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-70559 is an insecure deserialization vulnerability in the CMap loading mechanism of pdfminer.six, a popular Python PDF text extraction library. The flaw arises from the library's use of Python's pickle module to deserialize CMap cache files (.pickle.gz) without validation, enabling a low-privileged attacker who can write to a directory in the CMap search path to achieve arbitrary code execution or privilege escalation. All versions of pdfminer.six before 20251230 are affected. The vulnerability was published on November 7, 2025, and is explicitly noted as an incomplete fix for CVE-2025-64512. The GitHub Advisory Database assigns it a CVSS v3.1 score of 7.8 (High) with a local attack vector (GitHub Advisory).

Technical details

The root cause is CWE-502 (Deserialization of Untrusted Data) and CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes). The vulnerable code resides in pdfminer/cmapdb.py's _load_data method at line 246, where the library executes return type(str(name), (), pickle.loads(gzfile.read())) — directly deserializing the contents of a .pickle.gz file from the CMap search path without any integrity or authenticity checks. An attacker with write access to any directory listed in the CMAP_PATH environment variable or the default CMap directories can place a crafted malicious pickle file; when a privileged process (e.g., a root-owned PDF processing service) calls CMapDB.get_cmap(), the payload executes with that process's privileges. This vulnerability persists despite the patch applied for CVE-2025-64512 (commit b808ee05dd7f0c8ea8ec34bdf394d40e63501086), which did not fully eliminate the unsafe pickle deserialization path (GitHub Advisory, pdfminer Advisory).

Impact

Successful exploitation allows a low-privileged local attacker to execute arbitrary code with the privileges of the process running pdfminer.six — potentially root or a privileged service account. This can result in full system compromise, including high confidentiality impact (access to sensitive data), high integrity impact (modification of system files or data), and high availability impact (service disruption or persistence mechanisms). In multi-user or server environments where pdfminer.six processes PDFs as a privileged service, the vulnerability enables privilege escalation from a standard user to root, with potential for lateral movement and persistent backdoor installation (GitHub Advisory).

Exploitability

A detailed proof-of-concept (PoC) is publicly available as part of the GitHub Security Advisory, including createEvilPickle.py, evilmod.py, and processPDF.py scripts along with a Dockerfile to reproduce the attack (pdfminer Advisory). Exploitation requires local access and write permissions to a directory in the CMap search path, making it a local privilege escalation scenario rather than a remote attack. The EPSS score is approximately 0.114% (30th percentile), indicating a relatively low but non-negligible probability of exploitation in the wild (GitHub Advisory). No evidence of in-the-wild exploitation or threat actor attribution has been reported, and the vulnerability is not listed in the CISA KEV catalog.

Exploitation steps

  1. Identify target environment: Confirm that pdfminer.six (version < 20251230) is installed and used by a privileged process (e.g., a root-owned PDF processing service). Identify the CMAP_PATH environment variable or default CMap directories used by the application.
  2. Gain write access: As a low-privileged user, obtain write access to any directory listed in CMAP_PATH (e.g., a world-writable directory like /tmp/uploads or a shared upload folder).
  3. Craft malicious pickle payload: Create a Python script (createEvilPickle.py) that uses pickle and gzip to serialize a malicious object whose __reduce__ method executes arbitrary code (e.g., writing a file to /root/, spawning a reverse shell, or adding a backdoor user):
import pickle, gzip
class Evil:
    def __reduce__(self):
        import os
        return (os.system, ('id > /tmp/pwned',))
payload = pickle.dumps(Evil())
with gzip.open('/tmp/uploads/Evil.pickle.gz', 'wb') as f:
    f.write(payload)
  1. Place malicious file: Write the resulting Evil.pickle.gz file into the writable CMap directory, naming it to match a CMap name the privileged process will request.
  2. Trigger deserialization: Wait for or induce the privileged process to call CMapDB.get_cmap('Evil') — this occurs automatically when the process parses a PDF containing CJK fonts or when the CMap name is otherwise requested.
  3. Achieve code execution: The pickle.loads() call in cmapdb.py deserializes the malicious payload, executing the attacker's code with the privileges of the target process (e.g., root) (pdfminer Advisory).

Indicators of compromise

  • File System: Unexpected .pickle.gz files in CMap search path directories (e.g., /tmp/uploads/, default pdfminer CMap directories); files created in privileged locations (e.g., /root/) by non-root users; new cron jobs, SSH authorized keys, or SUID binaries created by the pdfminer service account.
  • Process: Unusual child processes spawned by the Python/pdfminer process (e.g., /bin/sh, bash, curl, wget, nc); unexpected network connections originating from the PDF processing service.
  • Logs: Python tracebacks or unexpected output in application logs related to CMap loading; audit logs (auditd) showing file creation in privileged directories by the pdfminer service user; inotifywait or filesystem audit events on CMap directories showing writes by low-privileged users followed by reads by privileged processes.
  • Network: Outbound connections from the PDF processing service to unknown external IPs, particularly if the malicious payload includes a reverse shell (pdfminer Advisory).

Mitigation and workarounds

Upgrade pdfminer.six to version 20251230 or later, which removes the dependency on unsafe pickle deserialization for CMap loading (GitHub Advisory). As a workaround prior to patching, restrict write permissions on all directories listed in CMAP_PATH and default CMap directories so that only trusted, privileged users can write to them — preventing low-privileged attackers from placing malicious files. Additionally, avoid running pdfminer.six as root or with elevated privileges; use a dedicated, least-privilege service account for PDF processing. Organizations should also audit existing CMap directories for unexpected .pickle.gz files as a precautionary measure.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pdfminer

Affected

sid

pdfminer: 20260107+dfsg-1

Fixed

trixie

pdfminer

Affected

Ubuntu

Fixed

bionic (esm-apps)

pdfminer: 20140328+dfsg-1ubuntu0.18.04.1~esm1

Fixed

devel

pdfminer

Not Affected

focal (esm-apps)

pdfminer: 20191020+dfsg-2ubuntu0.1~esm1

Fixed

jammy

pdfminer

Affected

jammy (esm-apps)

pdfminer: 20220319+dfsg-1ubuntu0.1~esm1

Fixed

noble

pdfminer

Affected

noble (esm-apps)

pdfminer: 20221105+dfsg-1ubuntu0.1~esm1

Fixed

resolute

pdfminer

Not Affected

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management