Feels like CVE-2025-64512 is a bit underrated. It can literally be used to run arbitrary code in a package used by more than 34k projects. For example, Microsoft Markitdown 0.1.3 (84k ⭐️ on GitHub), installed before December 1st, is vulnerable to arbitrary code execution. Microsoft released a patched version (0.1.4) on December 1st, but no security alerts. Other projects could be affected as well. CVE-2025-64512-Polyglot-PoC [1]: https://lnkd.in/dD6XNQbm

To view or add a comment, sign in

Explore content categories