Path Traversal Vulnerability in Patool by Wummel
CVE-2026-29509
5.3MEDIUM
What is CVE-2026-29509?
Patool versions prior to 4.0.5 are susceptible to a path traversal vulnerability in the safe_extract() function found in the py_tarfile.py module when utilized with Python versions earlier than 3.12. This vulnerability arises due to improper string comparison using os.path.commonprefix() instead of conducting a robust path-level comparison. Consequently, it permits attackers to craft malicious archive members with specially designed paths that can bypass containment checks, enabling the potential for arbitrary file write operations.
Affected Version(s)
patool 0
