[CVE-2026-4360] Tarfile.extract doesn't fully respect filter parameter
June 30, 2026
11:45 a.m.
There is a LOW severity vulnerability affecting CPython.
In the Tarfile.extract function, the filter parameter is not passed properly called when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract function.
Please see the linked CVE ID for the latest information on affected versions:
47
Age (days ago)
47
Last active (days ago)
0 comments
1 participants
participants (1)
-
Petr Viktorin