THREAT OPS › Threat News › [GHSA] GHSA-4mvj-m6j5-pmf7 (critical) — unstructured: Server-Side Request Forgery in the URL-based partitioning
[GHSA] GHSA-4mvj-m6j5-pmf7 (critical) — unstructured: Server-Side Request Forgery in the URL-based partitioning
GHSA-4mvj-m6j5-pmf7 Severity: critical CVE: CVE-2026-71428
unstructured: Server-Side Request Forgery in the URL-based partitioning
### Summary
Server-Side Request Forgery in `unstructured`. The `url=` argument of `partition()`, `partition_html()`, and `partition_md()` is fetched via `requests.get()` with no host validation. The response body is returned as `Element` text, so this is a **full-re
Indicators of compromise
- CVE-2026-71428cve
- http://127.0.0.1:9999/imdsurl
- http://127.0.0.1:9999url
Original source: https://github.com/advisories/GHSA-4mvj-m6j5-pmf7