PT-2026-35528 · Python · Cpython
Ggautomaton
+2
·
Published
2026-04-27
·
Updated
2026-04-29
·
CVE-2026-3087
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
CPython (affected versions not specified)
Description
On Windows, the
shutil.unpack archive() function fails to properly check for absolute paths within ZIP archives. If an archive contains a path with a drive letter (e.g., C:), files may be extracted outside of the intended target directory.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cpython