Skip to content
Exploit for CVE-2026

Exploit for CVE-2026

Sploitus • September 26, 2026

On Python ** Replace the placeholder dates below with the actual disclosure dates.

- `YYYY-MM-DD` — Vulnerability reported to the maintainers.

- `YYYY-MM-DD` — Vendor response / acknowledgment / no response.

- **2026-09-26** — Confirmed still unfixed in the latest release (`2.2.30`); extraction code remained unchanged.

Discovered and reported by **Rahul Karne**.

- Python `shutil.unpack_archive()` documentation

- PEP 706 — Filter for `tarfile.extractall`

- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory

- CVE-2007-4559 — Unsafe TAR extraction vulnerability class

This repository documents a coordinated-disclosure security finding and provides a harmless, self-contained proof of concept.

The PoC writes only inside the `--demo-root` directory specified by the user and performs no destructive actions.

Any network functionality included in the demonstration is limited to an optional local demonstration.

This material is provided for defensive security research and educational purposes.

Media inquiries: [email protected]. Full PoC (attacker server, traversal

archive, victim application) and additional technical detail available on request.

Extracted Entities

Attack Types (1)

CVEs (1)

CWE Weaknesses (1)

Domains (1)

Email Addresses (1)