Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-29509

Опубликовано: 26 июн. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfile.py when running on Python before 3.12, where the is_within_directory() helper uses os.path.commonprefix() for character-level string comparison instead of path-level comparison, allowing a crafted archive member path to bypass the containment check. Attackers can supply a malicious archive with specially crafted member paths to write arbitrary files.

A flaw was found in Patool. A remote attacker could exploit a path traversal vulnerability in the safe_extract() function by providing a specially crafted archive. This vulnerability arises because a helper function uses an insecure comparison method, allowing malicious paths to bypass security checks. Successful exploitation could enable the attacker to write arbitrary files to unintended locations on the system, potentially leading to information disclosure or system compromise.

Отчет

Red Hat does not ship patool in any Red Hat product. This vulnerability only affects the community Fedora package. Fedora maintainers have been notified via tracker.

Меры по смягчению последствий

Update patool to version 4.0.5 or later. Alternatively, use Python 3.12 or later, which includes built-in tarfile extraction filters that prevent path traversal attacks.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2493710patool: Patool: Arbitrary file write via path traversal in archive extraction

EPSS

Процентиль: 21%
0.00282
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 2 месяцев назад

Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfile.py when running on Python before 3.12, where the is_within_directory() helper uses os.path.commonprefix() for character-level string comparison instead of path-level comparison, allowing a crafted archive member path to bypass the containment check. Attackers can supply a malicious archive with specially crafted member paths to write arbitrary files.

CVSS3: 5.4
nvd
около 2 месяцев назад

Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfile.py when running on Python before 3.12, where the is_within_directory() helper uses os.path.commonprefix() for character-level string comparison instead of path-level comparison, allowing a crafted archive member path to bypass the containment check. Attackers can supply a malicious archive with specially crafted member paths to write arbitrary files.

CVSS3: 5.4
debian
около 2 месяцев назад

Patool before 4.0.5 contains a path traversal vulnerability in the saf ...

CVSS3: 5.4
github
около 2 месяцев назад

Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfile.py when running on Python before 3.12, where the is_within_directory() helper uses os.path.commonprefix() for character-level string comparison instead of path-level comparison, allowing a crafted archive member path to bypass the containment check. Attackers can supply a malicious archive with specially crafted member paths to write arbitrary files.

EPSS

Процентиль: 21%
0.00282
Низкий

5.4 Medium

CVSS3