VU#504749: PyMuPDF path traversal and arbitrary file write vulnerabilities
2026-03-04T20:25:46Z•8d93298f5b086979efc372b1bc2c4bdf7b6d7e347377b76ec3d67dedf9a46e5a
CVE-2025-14369CVE-2025-65586arbitrary-file-writeaudio-parsingcode-injectiondenial-of-servicehardcoded-secretsimage-parsinginteger-overflowjavascript-securityjwt-forgerykernel-driver-ioctlout-of-bounds-readpath-traversalprivilege-escalationprototype-pollutionremote-code-executionsstistack-buffer-overflow
What happened
Collection of multiple vulnerability advisories affecting a variety of open-source and commercial components. Issues include a PyMuPDF path‑traversal that allows arbitrary file writes, a CASL prototype‑pollution bug, an out‑of‑bounds read in libheif (CVE-2025-65586) causing crashes/DoS, a code‑injection flaw in binary-parser (pre-2.3.0) enabling arbitrary JS execution when untrusted input is used, hardcoded JWT/signing secrets in Open5GS WebUI enabling token forgery, a one‑byte stack overflow in libtasn1, an exploitable IOCTL in Safetica’s kernel driver permitting privileged process terminat
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 8d93298f5b086979efc372b1bc2c4bdf7b6d7e347377b76ec3d67dedf9a46e5a
- Enrichment time
- 2026-03-04T20:25:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.