{"id":"CVE-2026-7774","title":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory","summary":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to…","severity":"none","cwe":["CWE-22"],"published":"2026-06-04","updated":"2026-07-07","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7774","references":[{"url":"https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2","label":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6d","label":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efc","label":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117da","label":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558","label":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbf","label":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/c063191cb7f9170f9565e305f8aa2b79ab2bf609","label":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/149486","label":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/149487","label":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/","label":"cna@python.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/06/04/9","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00598,"epssPercentile":0.47057,"ingestedAt":"2026-07-07T18:42:24.242Z","slug":"CVE-2026-7774","body":"## Overview\n\ntarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}