PT-2026-52897 · Pypi · Patool
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Patool versions prior to 4.0.5
Description
A path traversal issue exists in the
safe extract() function within patoolib/programs/py tarfile.py when used with Python versions before 3.12. The is within directory() helper function utilizes os.path.commonprefix() for character-level string comparison rather than path-level comparison. This allows a specially crafted archive member path to bypass the containment check, enabling attackers to write arbitrary files to the system.Recommendations
Update Patool to version 4.0.5 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Patool