PT-2026-52897 · Pypi · Patool

·

CVE-2026-29509

·

Published

2026-06-26

·

Updated

2026-06-27

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Patool versions prior to 4.0.5
Description A path traversal issue exists in the safe extract() function within patoolib/programs/py tarfile.py when used with Python versions before 3.12. The is within directory() helper function utilizes os.path.commonprefix() for character-level string comparison rather than path-level comparison. This allows a specially crafted archive member path to bypass the containment check, enabling attackers to write arbitrary files to the system.
Recommendations Update Patool to version 4.0.5 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-29509

Affected Products

Patool