CVE-2026-7774: CWE-22 in Python Software Foundation CPython
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.
AI Analysis
Technical Summary
CVE-2026-7774 describes a directory traversal vulnerability in the Python Software Foundation's CPython implementation. The tarfile.data_filter function can be bypassed by specially crafted tar archives containing link entries such as symlinks with empty or directory-like names. This bypass allows tarfile.extractall() to write files outside the target extraction directory, potentially overwriting arbitrary files if the extracting process has sufficient permissions. The vulnerability affects CPython versions 3.14.0 and 3.15.0a1. No official patch or remediation level is provided in the available data, and no known exploits are reported in the wild.
Potential Impact
An attacker can craft a malicious tar archive that, when extracted using tarfile.extractall(), writes files outside the intended extraction directory. This can lead to unauthorized file creation or overwriting, potentially compromising system integrity or security depending on the permissions of the extracting process. The vulnerability does not require privileges or user interaction but does require the victim to extract the malicious archive.
Mitigation Recommendations
Patch status is not yet confirmed — check the Python Software Foundation advisory for current remediation guidance. Until a fix is available, avoid extracting untrusted tar archives using tarfile.extractall(). Consider using safer extraction methods that validate paths or restrict extraction to intended directories.
CVE-2026-7774: CWE-22 in Python Software Foundation CPython
Description
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.
CVSS v4.0
Score 6.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-7774 describes a directory traversal vulnerability in the Python Software Foundation's CPython implementation. The tarfile.data_filter function can be bypassed by specially crafted tar archives containing link entries such as symlinks with empty or directory-like names. This bypass allows tarfile.extractall() to write files outside the target extraction directory, potentially overwriting arbitrary files if the extracting process has sufficient permissions. The vulnerability affects CPython versions 3.14.0 and 3.15.0a1. No official patch or remediation level is provided in the available data, and no known exploits are reported in the wild.
Potential Impact
An attacker can craft a malicious tar archive that, when extracted using tarfile.extractall(), writes files outside the intended extraction directory. This can lead to unauthorized file creation or overwriting, potentially compromising system integrity or security depending on the permissions of the extracting process. The vulnerability does not require privileges or user interaction but does require the victim to extract the malicious archive.
Mitigation Recommendations
Patch status is not yet confirmed — check the Python Software Foundation advisory for current remediation guidance. Until a fix is available, avoid extracting untrusted tar archives using tarfile.extractall(). Consider using safer extraction methods that validate paths or restrict extraction to intended directories.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- PSF
- Date Reserved
- 2026-05-04T14:47:51.154Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a219e6ee29bf47b50b44825
Added to database: 06/04/2026, 15:49:02 UTC
Last enriched: 07/08/2026, 10:48:22 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 74
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.