
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3029 is a path traversal and arbitrary file write vulnerability in PyMuPDF's embedded_get function within __main__.py. It affects PyMuPDF versions >= 1.26.5 and < 1.26.7, developed by Artifex Software. The vulnerability was originally reported to CERT/CC on 2025-11-19, publicly disclosed on 2026-02-12, and the CVE was published on 2026-03-19. It carries a CVSS v3.1 base score of 7.5 (High) per Feedly/NVD, and a CVSS v4 base score of 6.9 (Moderate) per the GitHub Advisory (Github Advisory, CERT/CC VU#504749).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). The embedded_get function in __main__.py extracts embedded files from PDFs and, when the -output argument is not specified, uses the filename stored in the PDF's embedded file metadata directly as the output path without any sanitization or boundary checks. A crafted PDF can embed a file with a path-traversal filename (e.g., ../../etc/cron.d/malicious) so that when a user runs pymupdf embed-extract on it, the extracted content is written to an arbitrary location on the filesystem permitted by the executing user's privileges. The fix (commit 603cafe) adds checks to refuse writing outside the current directory or overwriting existing files unless the new -unsafe flag is explicitly passed (Github Advisory, PyMuPDF Commit, CERT/CC VU#504749).
Successful exploitation allows an attacker to write arbitrary file content to any location on the local filesystem accessible to the user running the pymupdf embed-extract command. If executed under a privileged account, this could overwrite system files, configuration files, or cron jobs, potentially leading to privilege escalation, service disruption, or security control bypass. The primary impact is on integrity (unauthorized file writes), with secondary risks to availability and, in escalation scenarios, confidentiality (CERT/CC VU#504749, Github Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.019% (6th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires that a victim user run the pymupdf embed-extract command against a maliciously crafted PDF without specifying the -output flag, making it a social engineering or supply-chain scenario rather than a remotely triggerable attack (CERT/CC VU#504749).
../../etc/cron.d/backdoor or ../../.ssh/authorized_keys). Using PyMuPDF itself, this can be done with document.embfile_add('entry', payload_bytes, filename='../../target/path', ufilename='../../target/path', desc='poc').python -m pymupdf embed-extract malicious.pdf -name entry (without the -output flag) from a working directory where the traversal path resolves to a sensitive location.embedded_get function uses the embedded metadata filename directly as the output path, writing the attacker-controlled payload bytes to the traversed location (e.g., a cron job, SSH authorized_keys, or web shell path).pymupdf embed-extract; files with path-traversal-style names (e.g., containing ../) appearing in sensitive directories such as /etc/cron.d/, ~/.ssh/, or web root directories.python -m pymupdf embed-extract or pymupdf embed-extract without the -output flag on externally sourced PDF files./etc/cron.d/, ~/.ssh/authorized_keys) coinciding with PDF processing activity.Upgrade PyMuPDF to version 1.26.7 or later, which introduces path safety checks in embedded_get that refuse to write outside the current directory or overwrite existing files unless the explicit -unsafe flag is passed (Github Advisory, PyMuPDF Commit). As a workaround for those unable to upgrade immediately, always use the -output flag with a safe, explicit output path when running pymupdf embed-extract, and restrict file system permissions for accounts that process PDFs. Additionally, monitor file system activity for unexpected file creation in sensitive directories (CERT/CC VU#504749).
The vulnerability was reported to CERT/CC by researcher Jangwoo Choe (UKO) and coordinated through the VINCE platform, with CERT/CC publishing VU#504749. Red Hat tracked the issue via Bugzilla (Bug 2449054) with high severity. OpenSUSE issued security announcements for affected packages. No significant social media controversy or broad media coverage has been observed beyond standard vulnerability tracking (CERT/CC VU#504749, bugzilla.redhat.com).
Fix availability across major Linux distributions and their releases.
bookworm
pymupdf
sid
pymupdf: 1.26.7+ds1-1
trixie
pymupdf: 1.25.4+ds1-3+deb13u1
devel
pymupdf
focal (esm-apps)
pymupdf
jammy
pymupdf
jammy (esm-apps)
pymupdf
noble
pymupdf
noble (esm-apps)
pymupdf
resolute
pymupdf
resolute (esm-apps)
pymupdf
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."