tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.
CVSS Details
- CVSS 4.0 Base Score: 6.9 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade python3 | Aug 17, 2026 | Jun 4, 2026 |
| Amazon_linux_2023 | — | Upgrade python3.9-debuginfoUpgrade python3.11-tkinterUpgrade python-unversioned-commandUpgrade python3.11Upgrade python3.14-freethreading-testUpgrade python3.14-testUpgrade python3.14-freethreading-debugUpgrade python3.14-freethreading-libsUpgrade python3.9-debugsourceUpgrade python3-idleUpgrade python3.14-freethreading-develUpgrade python3-libsUpgrade python3.11-testUpgrade python3.14Upgrade python3.11-libsUpgrade python3.14-debugUpgrade python3.14-freethreadingUpgrade python3.11-debuginfoUpgrade python3-develUpgrade python3.14-libsUpgrade python3Upgrade python3.11-debugsourceUpgrade python3.11-debugUpgrade python3.14-tkinterUpgrade python3.11-idleUpgrade python3.14-freethreading-idleUpgrade python3.14-freethreading-tkinterUpgrade python3-tkinterUpgrade python3-testUpgrade python3.14-debugsourceUpgrade python3.14-debuginfoUpgrade python3.11-develUpgrade python3.14-idleUpgrade python3.14-develUpgrade python3-debug | Jul 8, 2026 | Jun 4, 2026 |
| Debian | — | Upgrade python3.13 | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jun 4, 2026 |
| Ubuntu | — | Upgrade python3.14Upgrade python3.10Upgrade python3.12Upgrade libpython3.12t64Upgrade libpython3.14Upgrade libpython3.10 | Jul 6, 2026 | Jun 4, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub