Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-3087

Опубликовано: 19 мая 2026
Источник: msrc
EPSS Низкий

Описание

shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs

EPSS

Процентиль: 42%
0.00531
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

CVSS3: 7.5
nvd
3 месяца назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

CVSS3: 7.5
debian
3 месяца назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute W ...

CVSS3: 7.5
github
3 месяца назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

EPSS

Процентиль: 42%
0.00531
Низкий