CVE-2024-46455
Moderate
CVE-2024-46455 in github.com/Unstructured-IO/unstructured
CVE-2024-46455 in github.com/Unstructured-IO/unstructured
Exploit probability
0.5%
Published
December 10, 2024
Required by
Not available
Last source change
July 7, 2026
02 / AFFECTED SOFTWARE
Affected packages
135 explicit affected versions
135 explicit affected versions
04 / EVIDENCE
Source records
Open Source Vulnerabilities
GO-2024-3315
View original source
CVE-2024-46455 in github.com/Unstructured-IO/unstructured
Open Source Vulnerabilities
PYSEC-2026-1993
View original source
unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.
Open Source Vulnerabilities
GHSA-32r8-54hf-c9p3
View original source
unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.
05 / REFERENCES
Further evidence
- https://binarysouljour.me/cve-2024-46455
- https://github.com/Unstructured-IO/unstructured/tree/0.14.2
- https://nvd.nist.gov/vuln/detail/CVE-2024-46455
- https://github.com/Unstructured-IO/unstructured
- https://github.com/Unstructured-IO/unstructured/commit/171b5df09fc3346aba8ce91c04de5b3e094a86bd
- https://github.com/Unstructured-IO/unstructured/pull/3088
- https://github.com/advisories/GHSA-32r8-54hf-c9p3
- https://pypi.org/project/unstructured
- https://www.tenable.com/cve/CVE-2024-46455