← Späť na vyhľadávanie CVE

CVE-2026-4360

Tarfile

Popis

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter=-data- to the extract() function.

CVSS 5.3EPSS 0.27699999999999997%Riziko 0.54
Zobraziť zdroj
Zverejnené
2026-06-30 15:16:57
Dotknuté verzie
unknown
Typ
Knižnica
Posledná úprava
2026-08-06 01:16:29
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N