PT-2026-76655 · Pypi · Extract-Zip
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
extract-zip versions prior to 2.0.2
Description
Containment checks only verify the parent directory of each archive entry and ignore the entry's own final path component. This allows an archive containing two entries with identical names—a symlink targeting a location outside the destination followed by a regular file—to write through the planted symlink, resulting in an arbitrary file write outside the destination directory.
Recommendations
Update to version 2.0.2 or later.
Exploit
Fix
Path traversal
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Extract-Zip