PT-2026-33220 · Pypi · Gdown

Redyank

·

Published

2026-04-14

·

Updated

2026-05-01

·

CVE-2026-40491

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions gdown versions prior to 5.2.2
Description A Path Traversal issue exists within the extractall() function in the gdown/extractall.py file. The software fails to sanitize or validate the filenames of members within ZIP or TAR archives during extraction. This allows files to be written outside the intended destination directory, which can lead to arbitrary file overwrite and Remote Code Execution (RCE).
Recommendations Update to version 5.2.2. As a temporary workaround, restrict the use of the extractall() function when processing archives from untrusted sources.

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40491
GHSA-76HW-P97H-883F

Affected Products

Gdown