Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Unstructured

Unstructured Vendor Cyber Rating & Cyber Score

unstructured.io

At Unstructured, we're on a mission to give organizations access to all their data. We know the world runs on documents—from research reports and memos, to quarterly filings and plans of action. And yet, 80% of this information is trapped in inaccessible formats leading to inefficient decision-making and repetitive work. Until now. Unstructured captures this unstructured data wherever it lives and transforms it into AI-friendly JSON files for companies who are eager to fold AI into their business.


Unstructured A.I CyberSecurity Scoring

Unstructured
Company Information
Website:http://www.unstructured.io/
Employees number:103
Number of followers:26,623
NAICS:5112
Industry Type:Software Development
Homepage:unstructured.io
Unstructured Risk Score (AI oriented)
Between 700 and 749
logo
UnstructuredSoftware Development
Updated:
04/04/2026
741/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Unstructured Global Score (TPRM)
xxxx
logo
UnstructuredSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Unstructured
UnstructuredModerate
Current Score
741Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
743Before Incident
JULY 2026
743Before Incident
JUNE 2026
742Before Incident
MAY 2026
742Before Incident
APRIL 2026
741Before Incident
MARCH 2026
741Before Incident
FEBRUARY 2026
741Before Incident
JANUARY 2026
740Before Incident
DECEMBER 2025
740Before Incident
NOVEMBER 2025
739Before Incident
OCTOBER 2025
739Before Incident
SEPTEMBER 2025
739Before Incident
JANUARY 2025
752Before Incident
Cyber Attack
01 Jan 2025Unstructured
Google and Unstructured.io: Critical CVE-2025-64712 Vulnerability in Unstructured.io Exposes Amazon and Google to Remote Code Execution

Critical Path Traversal Flaw in Unstructured.io Exposes AI Data Pipelines to RCE

734After Incident
CRITICAL-18
GOOUNS1770992726
Critical Path Traversal Flaw in Unstructured.io Exposes AI Data Pipelines to RCE A severe vulnerability (CVE-2025-64712) in Unstructured.io, a widely used ETL library for AI data processing, has been disclosed, affecting 87% of Fortune 1000 companies, including Amazon, Google, and Bank of America. The flaw, rated 9.8 (Critical) on the CVSS scale, enables arbitrary file writes and remote code execution (RCE) via a path traversal exploit in the handling of Microsoft Outlook .msg attachments. The issue lies in the `partition_msg()` function, which processes email attachments by concatenating unvalidated filenames with temporary directories. Attackers can craft malicious .msg files with filenames like `../../root/.ssh/authorized_keys` or `../../etc/passwd`, allowing them to overwrite critical system files. This can lead to full server compromise, including data exfiltration, credential theft, or lateral movement within networks. Unstructured.io is a key tool for converting unstructured data such as PDFs, emails, and images into AI-ready formats, processing 80-90% of enterprise data. Its open-source library, used alongside managed SaaS APIs and integrations with S3, Google Drive, OneDrive, and Salesforce, powers frameworks like LlamaIndex and LangChain, amplifying the vulnerability’s reach across millions of deployments, including OpenWebUI. With over 4 million monthly downloads and dependencies embedded in ~100,000 GitHub repositories, the supply chain risk is significant. Major cloud providers, including Azure, AWS, and GCP, reference Unstructured.io in their documentation, embedding it in production AI pipelines. A patch is available via GitHub, and organizations are advised to upgrade immediately. The flaw affects all versions prior to the latest commit, with exploitation requiring no privileges and low attack complexity. CISA and vendors have emphasized the urgency of mitigating the risk to prevent RCE in enterprise environments.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Data Compromised: Potential data exfiltration, credential theftSystems Affected: AI data pipelines, enterprise serversOperational Impact: Full server compromise, lateral movement within networksIdentity Theft Risk: High (credential theft)
DATA BREACH
Type Of Data Compromised: Credentials, system files, potentially sensitive enterprise dataSensitivity Of Data: High (system files, credentials)Data Exfiltration: Possible.msgsystem files (e.g., /etc/passwd, authorized_keys)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Unstructured ?
?
What was Unstructured's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Unstructured's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Unstructured's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Unstructured's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Unstructured's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Unstructured's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Unstructured's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Unstructured's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Unstructured's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Unstructured's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Unstructured's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Unstructured's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Unstructured ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Unstructured's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?