PT-2026-46262 · Python+1 · Python+1

·

CVE-2026-7774

·

Published

2026-06-04

·

Updated

2026-08-01

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Python (affected versions not specified)
Description The tarfile.data filter can be bypassed using crafted link entries, such as symlinks with empty or directory-like names. This allows a malicious tar archive to redirect subsequent archive members outside the intended extraction directory, causing the tarfile.extractall() function to write files to arbitrary locations on the system, depending on the permissions of the process performing the extraction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-LIBPYTHON-2026-7774
BIT-PYTHON-2026-7774
BIT-PYTHON-MIN-2026-7774
CVE-2026-7774
ECHO-E345-EF13-BE4F
OESA-2026-2694
OESA-2026-2695
OPENSUSE-SU-2026:11101-1
OPENSUSE-SU-2026:11181-1
OPENSUSE-SU-2026:11426-1
OPENSUSE-SU-2026:11427-1
OPENSUSE-SU-2026:11428-1
PSF-2026-26
USN-8509-1

Affected Products

Linuxmint
Python