PT-2026-69945 · Pypi · Unearth
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
unearth versions prior to 0.18.2
Description
A path traversal issue exists in the
is within directory() function, which fails to normalize paths before validation. This allows ../ sequences to bypass directory containment checks. An attacker can use malicious tar archives containing symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.Recommendations
Update to the version containing commit 6c78164.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unearth