
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-70559 is an insecure deserialization vulnerability in the CMap loading mechanism of pdfminer.six, a popular Python PDF text extraction library. The flaw arises from the library's use of Python's pickle module to deserialize CMap cache files (.pickle.gz) without validation, enabling a low-privileged attacker who can write to a directory in the CMap search path to achieve arbitrary code execution or privilege escalation. All versions of pdfminer.six before 20251230 are affected. The vulnerability was published on November 7, 2025, and is explicitly noted as an incomplete fix for CVE-2025-64512. The GitHub Advisory Database assigns it a CVSS v3.1 score of 7.8 (High) with a local attack vector (GitHub Advisory).
The root cause is CWE-502 (Deserialization of Untrusted Data) and CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes). The vulnerable code resides in pdfminer/cmapdb.py's _load_data method at line 246, where the library executes return type(str(name), (), pickle.loads(gzfile.read())) — directly deserializing the contents of a .pickle.gz file from the CMap search path without any integrity or authenticity checks. An attacker with write access to any directory listed in the CMAP_PATH environment variable or the default CMap directories can place a crafted malicious pickle file; when a privileged process (e.g., a root-owned PDF processing service) calls CMapDB.get_cmap(), the payload executes with that process's privileges. This vulnerability persists despite the patch applied for CVE-2025-64512 (commit b808ee05dd7f0c8ea8ec34bdf394d40e63501086), which did not fully eliminate the unsafe pickle deserialization path (GitHub Advisory, pdfminer Advisory).
Successful exploitation allows a low-privileged local attacker to execute arbitrary code with the privileges of the process running pdfminer.six — potentially root or a privileged service account. This can result in full system compromise, including high confidentiality impact (access to sensitive data), high integrity impact (modification of system files or data), and high availability impact (service disruption or persistence mechanisms). In multi-user or server environments where pdfminer.six processes PDFs as a privileged service, the vulnerability enables privilege escalation from a standard user to root, with potential for lateral movement and persistent backdoor installation (GitHub Advisory).
A detailed proof-of-concept (PoC) is publicly available as part of the GitHub Security Advisory, including createEvilPickle.py, evilmod.py, and processPDF.py scripts along with a Dockerfile to reproduce the attack (pdfminer Advisory). Exploitation requires local access and write permissions to a directory in the CMap search path, making it a local privilege escalation scenario rather than a remote attack. The EPSS score is approximately 0.114% (30th percentile), indicating a relatively low but non-negligible probability of exploitation in the wild (GitHub Advisory). No evidence of in-the-wild exploitation or threat actor attribution has been reported, and the vulnerability is not listed in the CISA KEV catalog.
CMAP_PATH environment variable or default CMap directories used by the application.CMAP_PATH (e.g., a world-writable directory like /tmp/uploads or a shared upload folder).createEvilPickle.py) that uses pickle and gzip to serialize a malicious object whose __reduce__ method executes arbitrary code (e.g., writing a file to /root/, spawning a reverse shell, or adding a backdoor user):import pickle, gzip
class Evil:
def __reduce__(self):
import os
return (os.system, ('id > /tmp/pwned',))
payload = pickle.dumps(Evil())
with gzip.open('/tmp/uploads/Evil.pickle.gz', 'wb') as f:
f.write(payload)Evil.pickle.gz file into the writable CMap directory, naming it to match a CMap name the privileged process will request.CMapDB.get_cmap('Evil') — this occurs automatically when the process parses a PDF containing CJK fonts or when the CMap name is otherwise requested.pickle.loads() call in cmapdb.py deserializes the malicious payload, executing the attacker's code with the privileges of the target process (e.g., root) (pdfminer Advisory)..pickle.gz files in CMap search path directories (e.g., /tmp/uploads/, default pdfminer CMap directories); files created in privileged locations (e.g., /root/) by non-root users; new cron jobs, SSH authorized keys, or SUID binaries created by the pdfminer service account./bin/sh, bash, curl, wget, nc); unexpected network connections originating from the PDF processing service.auditd) showing file creation in privileged directories by the pdfminer service user; inotifywait or filesystem audit events on CMap directories showing writes by low-privileged users followed by reads by privileged processes.Upgrade pdfminer.six to version 20251230 or later, which removes the dependency on unsafe pickle deserialization for CMap loading (GitHub Advisory). As a workaround prior to patching, restrict write permissions on all directories listed in CMAP_PATH and default CMap directories so that only trusted, privileged users can write to them — preventing low-privileged attackers from placing malicious files. Additionally, avoid running pdfminer.six as root or with elevated privileges; use a dedicated, least-privilege service account for PDF processing. Organizations should also audit existing CMap directories for unexpected .pickle.gz files as a precautionary measure.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
pdfminer: 20140328+dfsg-1ubuntu0.18.04.1~esm1
devel
pdfminer
focal (esm-apps)
pdfminer: 20191020+dfsg-2ubuntu0.1~esm1
jammy
pdfminer
jammy (esm-apps)
pdfminer: 20220319+dfsg-1ubuntu0.1~esm1
noble
pdfminer
noble (esm-apps)
pdfminer: 20221105+dfsg-1ubuntu0.1~esm1
resolute
pdfminer
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."