File Metadata Modification Vulnerability in Python 3.12+
CVE-2024-12718
What is CVE-2024-12718?
A security flaw in the tarfile module of Python allows unauthorized modification of file metadata and permissions when extracting untrusted tar archives. Specifically, this vulnerability arises when using the TarFile.extractall() or TarFile.extract() methods with the filter parameter set to 'data' or 'tar' in Python versions 3.12 and later. Users should be cautious, as the default filter behavior changed in Python 3.14, which may inadvertently expose applications to risks. It is critical to avoid extracting archives from untrusted sources and to monitor project updates for potential patches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CPython 0 < 3.9.23
CPython 3.10.0 < 3.10.18
CPython 3.11.0 < 3.11.13
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
