onenote_parser
A Rust OneNote file parser
Activity
- Latest release
- 1mo ago
- Total releases
- 11
- Cadence
- ~44 days
- Last 12 months
- 6
Reach
- Downloads
- 14.0k
- Stars
- 84
Details
- License
- MPL-2.0
- First release
- Oct 16, 2020
| Version | Released | |
|---|---|---|
2.0.0
major
|
2.0.0
major
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
1.1.1
unknown
|
1.1.1
unknown
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.1.0
unknown
1 CVE
CVE-2026-46671
GHSA-4j5m-wc25-pvh7
May 21, 2026
Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
None
Low
ImpactA maliciously crafted The parser will bail out when the target file fails to parse as a OneNote section, so direct content exfiltration through the parser's return value is not practical, though file-existence probing and denial-of-service via large or special files remain possible. Anyone using PatchesFixed in onenote_parser 1.1.1. The fix rejects absolute paths, parent-directory components, and other invalid path characters in entry names, and additionally canonicalises the resolved path to confirm it stays inside the notebook's base directory. WorkaroundsFor users who cannot upgrade to 1.1.1:
Fixed in
1.1.1
References
Updated May 21, 2026 · Source: OSV.dev |
1.1.0
unknown
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
1.0.0
unknown
1 CVE
CVE-2026-46671
GHSA-4j5m-wc25-pvh7
May 21, 2026
Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
None
Low
ImpactA maliciously crafted The parser will bail out when the target file fails to parse as a OneNote section, so direct content exfiltration through the parser's return value is not practical, though file-existence probing and denial-of-service via large or special files remain possible. Anyone using PatchesFixed in onenote_parser 1.1.1. The fix rejects absolute paths, parent-directory components, and other invalid path characters in entry names, and additionally canonicalises the resolved path to confirm it stays inside the notebook's base directory. WorkaroundsFor users who cannot upgrade to 1.1.1:
Fixed in
1.1.1
References
Updated May 21, 2026 · Source: OSV.dev |
1.0.0
unknown
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.4.1
unknown
1 CVE
CVE-2026-46671
GHSA-4j5m-wc25-pvh7
May 21, 2026
Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
None
Low
ImpactA maliciously crafted The parser will bail out when the target file fails to parse as a OneNote section, so direct content exfiltration through the parser's return value is not practical, though file-existence probing and denial-of-service via large or special files remain possible. Anyone using PatchesFixed in onenote_parser 1.1.1. The fix rejects absolute paths, parent-directory components, and other invalid path characters in entry names, and additionally canonicalises the resolved path to confirm it stays inside the notebook's base directory. WorkaroundsFor users who cannot upgrade to 1.1.1:
Fixed in
1.1.1
References
Updated May 21, 2026 · Source: OSV.dev |
0.4.1
unknown
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.4.0
unknown
1 CVE
CVE-2026-46671
GHSA-4j5m-wc25-pvh7
May 21, 2026
Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
None
Low
ImpactA maliciously crafted The parser will bail out when the target file fails to parse as a OneNote section, so direct content exfiltration through the parser's return value is not practical, though file-existence probing and denial-of-service via large or special files remain possible. Anyone using PatchesFixed in onenote_parser 1.1.1. The fix rejects absolute paths, parent-directory components, and other invalid path characters in entry names, and additionally canonicalises the resolved path to confirm it stays inside the notebook's base directory. WorkaroundsFor users who cannot upgrade to 1.1.1:
Fixed in
1.1.1
References
Updated May 21, 2026 · Source: OSV.dev |
0.4.0
unknown
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.3.1
unknown
1 CVE
CVE-2026-46671
GHSA-4j5m-wc25-pvh7
May 21, 2026
Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
None
Low
ImpactA maliciously crafted The parser will bail out when the target file fails to parse as a OneNote section, so direct content exfiltration through the parser's return value is not practical, though file-existence probing and denial-of-service via large or special files remain possible. Anyone using PatchesFixed in onenote_parser 1.1.1. The fix rejects absolute paths, parent-directory components, and other invalid path characters in entry names, and additionally canonicalises the resolved path to confirm it stays inside the notebook's base directory. WorkaroundsFor users who cannot upgrade to 1.1.1:
Fixed in
1.1.1
References
Updated May 21, 2026 · Source: OSV.dev |
0.3.1
unknown
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.3.0
unknown
1 CVE
CVE-2026-46671
GHSA-4j5m-wc25-pvh7
May 21, 2026
Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
None
Low
ImpactA maliciously crafted The parser will bail out when the target file fails to parse as a OneNote section, so direct content exfiltration through the parser's return value is not practical, though file-existence probing and denial-of-service via large or special files remain possible. Anyone using PatchesFixed in onenote_parser 1.1.1. The fix rejects absolute paths, parent-directory components, and other invalid path characters in entry names, and additionally canonicalises the resolved path to confirm it stays inside the notebook's base directory. WorkaroundsFor users who cannot upgrade to 1.1.1:
Fixed in
1.1.1
References
Updated May 21, 2026 · Source: OSV.dev |
0.3.0
unknown
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.2.1
unknown
1 CVE
CVE-2026-46671
GHSA-4j5m-wc25-pvh7
May 21, 2026
Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
None
Low
ImpactA maliciously crafted The parser will bail out when the target file fails to parse as a OneNote section, so direct content exfiltration through the parser's return value is not practical, though file-existence probing and denial-of-service via large or special files remain possible. Anyone using PatchesFixed in onenote_parser 1.1.1. The fix rejects absolute paths, parent-directory components, and other invalid path characters in entry names, and additionally canonicalises the resolved path to confirm it stays inside the notebook's base directory. WorkaroundsFor users who cannot upgrade to 1.1.1:
Fixed in
1.1.1
References
Updated May 21, 2026 · Source: OSV.dev |
0.2.1
unknown
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.2.0
unknown
1 CVE
CVE-2026-46671
GHSA-4j5m-wc25-pvh7
May 21, 2026
Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
None
Low
ImpactA maliciously crafted The parser will bail out when the target file fails to parse as a OneNote section, so direct content exfiltration through the parser's return value is not practical, though file-existence probing and denial-of-service via large or special files remain possible. Anyone using PatchesFixed in onenote_parser 1.1.1. The fix rejects absolute paths, parent-directory components, and other invalid path characters in entry names, and additionally canonicalises the resolved path to confirm it stays inside the notebook's base directory. WorkaroundsFor users who cannot upgrade to 1.1.1:
Fixed in
1.1.1
References
Updated May 21, 2026 · Source: OSV.dev |
0.2.0
unknown
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.1.0
unknown
1 CVE
CVE-2026-46671
GHSA-4j5m-wc25-pvh7
May 21, 2026
Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
None
Low
ImpactA maliciously crafted The parser will bail out when the target file fails to parse as a OneNote section, so direct content exfiltration through the parser's return value is not practical, though file-existence probing and denial-of-service via large or special files remain possible. Anyone using PatchesFixed in onenote_parser 1.1.1. The fix rejects absolute paths, parent-directory components, and other invalid path characters in entry names, and additionally canonicalises the resolved path to confirm it stays inside the notebook's base directory. WorkaroundsFor users who cannot upgrade to 1.1.1:
Fixed in
1.1.1
References
Updated May 21, 2026 · Source: OSV.dev |
0.1.0
unknown
Dependencies (9)
+ 1 more
Changelog
|