CVE-2026-4360
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.
Scoring
- Severity
- LOW
- CVSS base score
- 2
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.28%
- CWE
- CWE-281
- Published
- 2026-06-30
- Last modified
- 2026-08-13
Affected products
- Python Software Foundation CPython
- Python Software Foundation CPython
- Python Software Foundation CPython
- Python Software Foundation CPython
- Python Software Foundation CPython
- Python Software Foundation CPython
Weakness type
Related vulnerabilities
- CVE-2026-88016 — rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
- CVE-2026-58510 — GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- CVE-2025-14779 — Improper Access Control via Secret Type Management API in WSO2 Identity Server
- CVE-2026-23556 — oxenstored keeps quota related use counts across domain destruction
- CVE-2026-58494 — Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination
- CVE-2026-44947 — Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher
- CVE-2026-40767 — WordPress wpForo Forum plugin < 3.0.2 - Broken Access Control vulnerability
- CVE-2024-47270 — Improper preservation of permissions vulnerability in Archiving Push functionality in Synology...