Path Traversal Vulnerability in GuardDog CLI Tool by DataDog
CVE-2026-22871
8.7HIGH
What is CVE-2026-22871?
The GuardDog CLI tool, which identifies malicious PyPI packages, contains a path traversal vulnerability in its safe_extract() function, allowing malicious packages to write arbitrary files outside the designated extraction directory. This flaw could potentially enable remote code execution on systems running earlier versions of GuardDog, effectively compromising system integrity. The vulnerability has been addressed in version 2.7.1, emphasizing the importance of updating to safeguard against exploitation.
Affected Version(s)
guarddog < 2.7.1
