PT-2026-91410 · Python · Cpython
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CPython versions prior to 3.14
Description
The
tarfile module's data and extraction filters are susceptible to a bypass when processing crafted archives containing a hard link that targets a symbolic link. This issue occurs during the execution of the extractall() function, potentially allowing an attacker to modify the permissions or modification time of files located outside the intended destination directory. Additionally, it may lead to the exposure of the contents of such files within the extracted directory tree. Non-link entries are not affected.Recommendations
Update to a version later than 3.13.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cpython