CVE-2026-3029: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-3029 is a path traversal and arbitrary file write vulnerability in PyMuPDF's embedded_get function within __main__.py. It affects PyMuPDF versions >= 1.26.5 and < 1.26.7, developed by Artifex Software. The vulnerability was originally reported to CERT/CC on 2025-11-19, publicly disclosed on 2026-02-12, and the CVE was published on 2026-03-19. It carries a CVSS v3.1 base score of 7.5 (High) per Feedly/NVD, and a CVSS v4 base score of 6.9 (Moderate) per the GitHub Advisory (Github Advisory, CERT/CC VU#504749).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). The embedded_get function in __main__.py extracts embedded files from PDFs and, when the -output argument is not specified, uses the filename stored in the PDF's embedded file metadata directly as the output path without any sanitization or boundary checks. A crafted PDF can embed a file with a path-traversal filename (e.g., ../../etc/cron.d/malicious) so that when a user runs pymupdf embed-extract on it, the extracted content is written to an arbitrary location on the filesystem permitted by the executing user's privileges. The fix (commit 603cafe) adds checks to refuse writing outside the current directory or overwriting existing files unless the new -unsafe flag is explicitly passed (Github Advisory, PyMuPDF Commit, CERT/CC VU#504749).

Impact

Successful exploitation allows an attacker to write arbitrary file content to any location on the local filesystem accessible to the user running the pymupdf embed-extract command. If executed under a privileged account, this could overwrite system files, configuration files, or cron jobs, potentially leading to privilege escalation, service disruption, or security control bypass. The primary impact is on integrity (unauthorized file writes), with secondary risks to availability and, in escalation scenarios, confidentiality (CERT/CC VU#504749, Github Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.019% (6th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires that a victim user run the pymupdf embed-extract command against a maliciously crafted PDF without specifying the -output flag, making it a social engineering or supply-chain scenario rather than a remotely triggerable attack (CERT/CC VU#504749).

Exploitation steps

  1. Craft a malicious PDF: Create a PDF with an embedded file whose stored filename contains a path traversal sequence (e.g., ../../etc/cron.d/backdoor or ../../.ssh/authorized_keys). Using PyMuPDF itself, this can be done with document.embfile_add('entry', payload_bytes, filename='../../target/path', ufilename='../../target/path', desc='poc').
  2. Deliver the PDF to the target: Distribute the crafted PDF to a user or system that processes PDFs with PyMuPDF's CLI (e.g., via email, file share, or as part of a document processing pipeline).
  3. Trigger extraction: Induce the victim to run python -m pymupdf embed-extract malicious.pdf -name entry (without the -output flag) from a working directory where the traversal path resolves to a sensitive location.
  4. Achieve arbitrary file write: The embedded_get function uses the embedded metadata filename directly as the output path, writing the attacker-controlled payload bytes to the traversed location (e.g., a cron job, SSH authorized_keys, or web shell path).
  5. Escalate or persist: If the written file is a cron job, SSH key, or web-accessible script, the attacker can achieve code execution or persistent access (CERT/CC VU#504749, PyMuPDF Commit).

Indicators of compromise

  • File System: Unexpected files created outside the working directory after running pymupdf embed-extract; files with path-traversal-style names (e.g., containing ../) appearing in sensitive directories such as /etc/cron.d/, ~/.ssh/, or web root directories.
  • Logs: Shell history or audit logs showing invocations of python -m pymupdf embed-extract or pymupdf embed-extract without the -output flag on externally sourced PDF files.
  • Process: Unexpected processes spawned shortly after PDF extraction (e.g., new cron jobs executing, SSH logins from unknown keys).
  • File System: Modification timestamps on system files (e.g., /etc/cron.d/, ~/.ssh/authorized_keys) coinciding with PDF processing activity.

Mitigation and workarounds

Upgrade PyMuPDF to version 1.26.7 or later, which introduces path safety checks in embedded_get that refuse to write outside the current directory or overwrite existing files unless the explicit -unsafe flag is passed (Github Advisory, PyMuPDF Commit). As a workaround for those unable to upgrade immediately, always use the -output flag with a safe, explicit output path when running pymupdf embed-extract, and restrict file system permissions for accounts that process PDFs. Additionally, monitor file system activity for unexpected file creation in sensitive directories (CERT/CC VU#504749).

Community reactions

The vulnerability was reported to CERT/CC by researcher Jangwoo Choe (UKO) and coordinated through the VINCE platform, with CERT/CC publishing VU#504749. Red Hat tracked the issue via Bugzilla (Bug 2449054) with high severity. OpenSUSE issued security announcements for affected packages. No significant social media controversy or broad media coverage has been observed beyond standard vulnerability tracking (CERT/CC VU#504749, bugzilla.redhat.com).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pymupdf

Affected

sid

pymupdf: 1.26.7+ds1-1

Fixed

trixie

pymupdf: 1.25.4+ds1-3+deb13u1

Fixed

Ubuntu

Unknown

devel

pymupdf

Not Affected

focal (esm-apps)

pymupdf

Unknown

jammy

pymupdf

Unknown

jammy (esm-apps)

pymupdf

Unknown

noble

pymupdf

Unknown

noble (esm-apps)

pymupdf

Unknown

resolute

pymupdf

Not Affected

resolute (esm-apps)

pymupdf

Not Affected

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management