PT-2026-2805 · Guarddog · Guarddog

Dwbruijn

·

Published

2026-01-13

·

Updated

2026-01-21

·

CVE-2026-22871

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GuardDog versions prior to 2.7.1
Description GuardDog is a command-line interface (CLI) tool used to identify malicious PyPI packages. A path traversal flaw exists in the safe extract() function, potentially allowing malicious PyPI packages to write files to locations outside the intended extraction directory. This could lead to arbitrary file overwrite and remote code execution. The vulnerable function is safe extract().
Recommendations Update GuardDog to version 2.7.1 or later.

Exploit

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-22871
GHSA-XG9W-VG3G-6M68

Affected Products

Guarddog