CVE-2025-70559 is an insecure deserialization vulnerability in pdfminer.six versions before 20251230. The CMap loading mechanism deserializes cached CMap data using Python pickle without validating its contents. An attacker who can place a malicious serialized cache file in a location searched by the application can cause attacker-controlled code to execute when a trusted process loads the file. The flaw resulted from an incomplete fix for CVE-2025-64512.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit generator consisting of a README and one executable script, exploit.py. The script does not directly attack a remote service over HTTP; instead, it creates two files intended for use against a vulnerable server-side PDF processing pipeline. First, it serializes a Python object whose __reduce__ method causes os.system to execute a bash reverse shell command, then compresses that pickle into sh.pickle.gz. Second, it builds a minimal PDF file, trigger.pdf, whose font Encoding field is manipulated to contain a hex-escaped server-side filesystem path pointing to the expected pickle location under the upload directory. The apparent exploitation chain is: upload or place the malicious pickle in a directory accessible to the target application, then cause the application to process trigger.pdf with a vulnerable pdfminer-based workflow that interprets the crafted Encoding path and subsequently loads/deserializes the gzip-compressed pickle. Successful exploitation yields remote code execution and a reverse shell to the attacker-supplied LHOST and LPORT. Repository structure is minimal: README.md only gives usage guidance and notes that the upload directory may need to be changed; exploit.py contains all exploit logic, including argument parsing, payload construction, PDF generation, and output of the two artifacts. The exploit is operational rather than a mere proof of concept because it includes a working payload, but it is not framework-based and requires manual targeting details such as the correct upload directory and a vulnerable target workflow.
This repository is a small standalone Python proof-of-concept exploit consisting of one code file (exploit.py) and a minimal README. The script generates two artifacts: (1) sh.pickle.gz, a gzip-compressed Python pickle whose deserialization triggers os.system, and (2) trigger.pdf, a crafted PDF whose font Encoding field is set to a hex-encoded absolute server-side path. The intended attack chain is that a vulnerable pdfminer-based application processes the PDF, derives or accesses a cache/object path based on the attacker-controlled Encoding value, and then loads the attacker-written pickle from the target upload directory. Upon deserialization, the payload runs a bash reverse shell using /dev/tcp to connect back to the supplied LHOST and LPORT. The exploit is operational but not highly flexible: it hardcodes the payload filename as sh and defaults the target directory to /var/www/research.bedside.htb/uploads, though this can be overridden via a third command-line argument. Repository structure is minimal and purpose-built for exploitation rather than detection or research automation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.