You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
weave version 0.52.17 depends on the polyfile-weave package, which in turn pins pdfminer.six==20240706. This version of pdfminer.six is affected by CVE-2025-64512, a vulnerability that can lead to arbitrary code execution when processing a maliciously crafted PDF.
As a result, any Weave usage path that exercises polyfile-weave's PDF parsing on untrusted input may be exploitable.
victoria-latynina, wsng01, hillolsarkersanofi and saif-fares