PT-2026-3523 · Unknown+1 · Jaraco.Context+1
Tsigouris007
·
Published
2026-01-13
·
Updated
2026-05-21
·
CVE-2026-23949
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
jaraco.context versions prior to 6.1.0
Description
jaraco.context, a software package providing decorators and context managers, contains a path traversal issue in the
jaraco.context.tarball() function. The issue allows attackers to extract files outside the intended directory when processing malicious tar archives. The vulnerability arises because the strip first component filter incorrectly handles ../ sequences within paths, enabling traversal attacks. This is also susceptible to nested tarball attacks involving multi-level tar files. The tarball() function is vulnerable.Recommendations
Update jaraco.context to version 6.1.0 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Os
Jaraco.Context