« Volver al listado

CVE-2026-7774

Estado: Pendiente de análisisMedia (6.9)—

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-7774",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-7774",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-04T17:27:23.917872Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "cna@python.org",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 6.9,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "ACTIVE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "cna@python.org",
      "affectedData": [
        {
          "repo": "https://github.com/python/cpython",
          "vendor": "Python Software Foundation",
          "modules": [
            "tarfile"
          ],
          "product": "CPython",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "3.10.21",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.11.0",
              "lessThan": "3.11.16",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.12.0",
              "lessThan": "3.12.14",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.13.0",
              "lessThan": "3.13.14",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.14.0",
              "lessThan": "3.14.6",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.15.0a1",
              "lessThan": "3.15.0b2",
              "versionType": "python"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-06-04T16:16:42.103",
  "references": [
    {
      "url": "https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6d",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efc",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117da",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbf",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/c063191cb7f9170f9565e305f8aa2b79ab2bf609",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/issues/149486",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/pull/149487",
      "source": "cna@python.org"
    },
    {
      "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/",
      "source": "cna@python.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/06/04/9",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cna@python.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process."
    },
    {
      "lang": "es",
      "value": "tarfile.data_filter podría ser eludido utilizando entradas de enlace manipuladas, incluyendo enlaces simbólicos con nombres vacíos o similares a directorios, para redirigir miembros posteriores del archivo fuera del directorio de extracción previsto. Esto permitía que un archivo tar malicioso causara que tarfile.extractall() escribiera archivos fuera del directorio de destino, sujeto a los permisos del proceso de extracción."
    }
  ],
  "lastModified": "2026-08-13T01:16:55.783",
  "sourceIdentifier": "cna@python.org"
}