Impact
The CPython tarfile module accepts archive entries that combine a hard link pointing to a symbolic link, allowing the extraction to modify the permissions or modification time of a file outside the intended destination directory or to expose the contents of that file within the extraction tree. This flaw is a form of improper handling of link references (CWE‑59). An attacker who can supply a crafted archive to a program that uses tarfile extraction can cause sensitive files to be altered or leak private data, potentially undermining system integrity and confidentiality without executing arbitrary code.
Affected Systems
The vulnerability affects CPython releases 3.13 and older. Python applications that employ the tarfile module to unpack archives—especially those processing untrusted inputs—are at risk. The issue is rooted in the Python Software Foundation’s CPython code base and thus applies universally to these CPython versions regardless of operating system.
Risk and Exploitability
The vulnerability has a CVSS score of 8.4, indicating a high severity. The EPSS score is less than 1%, suggesting a low exploitation probability, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is the delivery of a malicious tar archive to a target system that runs Python code with tarfile extraction capabilities; the attacker need not possess elevated privileges prior to exploitation. Because the flaw can modify files outside the extraction directory, it can be used to tamper with configuration files or to leak sensitive data that otherwise would remain inaccessible. The impact is limited to the file system level and does not directly provide remote code execution, but the ability to manipulate or read arbitrary files can facilitate broader compromise if paired with other weaknesses.
OpenCVE Enrichment