THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-4mvj-m6j5-pmf7 (critical) — unstructured: Server-Side Request Forgery in the URL-based partitioning

[GHSA] GHSA-4mvj-m6j5-pmf7 (critical) — unstructured: Server-Side Request Forgery in the URL-based partitioning

highgithub_advisoriesPublished 2026-09-03

GHSA-4mvj-m6j5-pmf7 Severity: critical CVE: CVE-2026-71428

unstructured: Server-Side Request Forgery in the URL-based partitioning

### Summary

Server-Side Request Forgery in `unstructured`. The `url=` argument of `partition()`, `partition_html()`, and `partition_md()` is fetched via `requests.get()` with no host validation. The response body is returned as `Element` text, so this is a **full-re

Indicators of compromise

Original source: https://github.com/advisories/GHSA-4mvj-m6j5-pmf7