CVE-2026-3029
CVE-2026-3029
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF version, 1.26.5.
| Vendor | artifex software inc. *pymupdf* |
| Product | pymupdf |
| Published | Mar 19, 2026 |
| Last Updated | Jul 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for artifex software inc. *pymupdf* pymupdf
Be the first to know when new high vulnerabilities affecting artifex software inc. *pymupdf* pymupdf are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Artifex Software Inc. *PyMuPDF* / PyMuPDF
1.26.5 < 1.26.7
References
github.com: http://github.com/pymupdf/PyMuPDF github.com: http://github.com/pymupdf/PyMuPDF/commit/603cafe38a183b8bab34f16d05043b4185d8d40a kb.cert.org: https://www.kb.cert.org/vuls/id/504749 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-3029 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2449054 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3029.json