Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-3087

Опубликовано: 27 апр. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

If shutil.unpack_archive() is given a ZIP archive with an absolute Windows path containing a drive (C:\\...) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
Версия до 3.14.4 (включая)
cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha7:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha8:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 42%
0.00531
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

msrc
2 месяца назад

shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs

CVSS3: 7.5
debian
3 месяца назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute W ...

CVSS3: 7.5
github
3 месяца назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

EPSS

Процентиль: 42%
0.00531
Низкий

7.5 High

CVSS3

Дефекты

CWE-22