Tarfile Module Vulnerability in Python Software
CVE-2025-13462

2LOW

What is CVE-2025-13462?

The Tarfile module in Python software is susceptible to improper input handling, where normalization of AREGTYPE blocks is incorrectly applied to DIRTYPE during the processing of multi-block members like GNUTYPE_LONGNAME and GNUTYPE_LONGLINK. This flaw can lead to crafted tar archives being misinterpreted by the Tarfile module, potentially causing security risks compared to other implementations. Proper handling and validation of tar archive inputs are crucial to mitigate exploitation of this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

CPython 0 < 3.15.0

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.