PT-2026-51546 · Pypi+1 · Tarfile+1
CVSS v4.0
7.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Python tarfile (affected versions not specified)
Description
A flaw exists in the
extractall() function when using the 'data' or 'tar' filters. A specially crafted archive containing a hardlink that references a symlink stored at a deeper path can bypass these filters. The extraction process validates the symlink at its original archived location but recreates it at the shallower path of the hardlink. This allows a relative target to escape the destination directory, enabling a malicious archive to create symlinks that point outside the intended folder, which can lead to unauthorized file reads or writes outside the destination.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Path traversal
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rocky Linux
Tarfile