Path Traversal Vulnerability in Patool by Wummel
CVE-2026-29509

5.3MEDIUM

Key Information:

Vendor

Wummel

Status
Vendor
CVE Published:
26 June 2026

What is CVE-2026-29509?

Patool versions prior to 4.0.5 are susceptible to a path traversal vulnerability in the safe_extract() function found in the py_tarfile.py module when utilized with Python versions earlier than 3.12. This vulnerability arises due to improper string comparison using os.path.commonprefix() instead of conducting a robust path-level comparison. Consequently, it permits attackers to craft malicious archive members with specially designed paths that can bypass containment checks, enabling the potential for arbitrary file write operations.

Affected Version(s)

patool 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CodeAnt AI Security
VulnCheck
.