There is a HIGH severity vulnerability affecting CPython.

In CPython 3.13 and earlier, the tarfile module's data and tar extraction
filters are vulnerable to crafted archives containing a hard link to a
symbolic link. Such archives may cause extraction to modify the permissions
or modification time of a file outside the destination directory, or expose
the contents of that file within the extracted tree.

Please see the linked CVE ID for the latest information on affected
versions:

* https://www.cve.org/CVERecord?id=CVE-2026-82049
* https://github.com/python/cpython/pull/157192

-- 
Stan Ulbrych  (https://stan.ulbrych.org)
_______________________________________________
Security-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3//lists/security-announce.python.org
Member address: [email protected]

Reply via email to