On Python ** Replace the placeholder dates below with the actual disclosure dates.
- `YYYY-MM-DD` — Vulnerability reported to the maintainers.
- `YYYY-MM-DD` — Vendor response / acknowledgment / no response.
- **2026-09-26** — Confirmed still unfixed in the latest release (`2.2.30`); extraction code remained unchanged.
Discovered and reported by **Rahul Karne**.
- Python `shutil.unpack_archive()` documentation
- PEP 706 — Filter for `tarfile.extractall`
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory
- CVE-2007-4559 — Unsafe TAR extraction vulnerability class
This repository documents a coordinated-disclosure security finding and provides a harmless, self-contained proof of concept.
The PoC writes only inside the `--demo-root` directory specified by the user and performs no destructive actions.
Any network functionality included in the demonstration is limited to an optional local demonstration.
This material is provided for defensive security research and educational purposes.
Media inquiries: [email protected]. Full PoC (attacker server, traversal
archive, victim application) and additional technical detail available on request.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
