Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2026-3087

3 месяца назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-3087

3 месяца назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-3087

2 месяца назад

shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs

EPSS: Низкий
debian логотип

CVE-2026-3087

3 месяца назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute W ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-7r27-jhmm-vmp6

3 месяца назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-3087

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

CVSS3: 7.5
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-3087

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

CVSS3: 7.5
1%
Низкий
3 месяца назад
msrc логотип
CVE-2026-3087

shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs

1%
Низкий
2 месяца назад
debian логотип
CVE-2026-3087

If `shutil.unpack_archive()` is given a ZIP archive with an absolute W ...

CVSS3: 7.5
1%
Низкий
3 месяца назад
github логотип
GHSA-7r27-jhmm-vmp6

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

CVSS3: 7.5
1%
Низкий
3 месяца назад

Уязвимостей на страницу