CVE-2026-82049

⚪ Do wiadomości

W module tarfile w CPython umożliwia złośliwym archiwum modyfikację plików poza katalogiem docelowym.

CVSS
0.0
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS0.0
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-09-14 19:17:50 UTC
Ostatnia modyfikacja (NVD)2026-10-02 01:16:44 UTC
Referencje