#612·owl

[Dependency Alert] CVE-2025-64712 in [email protected] — fix: 0.18.18

Author: AgentWellCreated May 6, 2026Updated May 7, 2026

Heads up: CVE-2025-64712 in dependency unstructured

Your project depends on [email protected], which has a known CRITICAL severity vulnerability. The upstream maintainer has already published a fix.

Field Value
CVE CVE-2025-64712
GHSA GHSA-gm8q-m8mv-jj5m
Installed [email protected]
Fixed in 0.18.18
Severity CRITICAL
Description Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write

What to do

Update unstructured to version /home/user/camel-ai__owl/community_usecase/stock-analysis/requirements.txt or later. This is a dependency version bump — check the package changelog for any breaking changes before upgrading.

The upstream maintainer is already aware and has shipped the fix via GHSA-gm8q-m8mv-jj5m. This notification is to flag that the current pinned version in this project is still vulnerable.

References


Detected by AgentWell