[Dependency Alert] CVE-2025-64712 in [email protected] — fix: 0.18.18
Author: AgentWellCreated May 6, 2026Updated May 7, 2026
Heads up: CVE-2025-64712 in dependency unstructured
Your project depends on [email protected], which has a known CRITICAL severity vulnerability. The upstream maintainer has already published a fix.
| Field | Value |
|---|---|
| CVE | CVE-2025-64712 |
| GHSA | GHSA-gm8q-m8mv-jj5m |
| Installed | [email protected] |
| Fixed in | 0.18.18 |
| Severity | CRITICAL |
| Description | Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write |
What to do
Update unstructured to version /home/user/camel-ai__owl/community_usecase/stock-analysis/requirements.txt or later. This is a dependency version bump — check the package changelog for any breaking changes before upgrading.
The upstream maintainer is already aware and has shipped the fix via GHSA-gm8q-m8mv-jj5m. This notification is to flag that the current pinned version in this project is still vulnerable.
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-64712
- GHSA: https://github.com/advisories/GHSA-gm8q-m8mv-jj5m
Detected by AgentWell
Source: camel-ai/owl