PT-2026-64148 · Datasets · Datasets
CVSS v3.1
6.6
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Datasets versions prior to 5.01
Description
A symlink-following issue exists in the
Extractor.extract() function. Local attackers can write arbitrary files by pre-planting symbolic links (shortcuts that point to another file or directory) at predictable output paths. In shared-cache environments, this allows the redirection of archive extraction to arbitrary filesystem locations, which can lead to the overwriting of sensitive files, privilege escalation, or code execution.Recommendations
Update to the version containing commit ad2d853.
As a temporary mitigation, restrict access to the
Extractor.extract() function to prevent unauthorized users from triggering archive extractions.Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Datasets