VU#504749: PyMuPDF path traversal and arbitrary file write vulnerabilities

2026-03-04T20:25:46Z8d93298f5b086979efc372b1bc2c4bdf7b6d7e347377b76ec3d67dedf9a46e5a
CVE-2025-14369CVE-2025-65586arbitrary-file-writeaudio-parsingcode-injectiondenial-of-servicehardcoded-secretsimage-parsinginteger-overflowjavascript-securityjwt-forgerykernel-driver-ioctlout-of-bounds-readpath-traversalprivilege-escalationprototype-pollutionremote-code-executionsstistack-buffer-overflow

What happened

Collection of multiple vulnerability advisories affecting a variety of open-source and commercial components. Issues include a PyMuPDF path‑traversal that allows arbitrary file writes, a CASL prototype‑pollution bug, an out‑of‑bounds read in libheif (CVE-2025-65586) causing crashes/DoS, a code‑injection flaw in binary-parser (pre-2.3.0) enabling arbitrary JS execution when untrusted input is used, hardcoded JWT/signing secrets in Open5GS WebUI enabling token forgery, a one‑byte stack overflow in libtasn1, an exploitable IOCTL in Safetica’s kernel driver permitting privileged process termi­n­at

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
8d93298f5b086979efc372b1bc2c4bdf7b6d7e347377b76ec3d67dedf9a46e5a
Enrichment time
2026-03-04T20:25:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.