CVE-2025-4517General

LOWCVSS 9.4 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-02-16); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-16: 2Mentions · 2026-03-05: 1Mentions · 2026-03-18: 1Mentions · 2026-06-29: 1PoC Mentioned / Linked · 2026-02-16: 1PoC Mentioned / Linked · 2026-06-29: 1Exploit Tool / Code · 2026-02-16: 1Technical Details · 2026-02-16: 2Technical Details · 2026-06-29: 102-1603-0503-1806-29
Signal classification4 categories
General
240.0%
Exploit
120.0%
PoC
120.0%
Disclosure
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-162
Exploit1PoC1
2026-03-051
General1
2026-03-181
General1
2026-06-291
Disclosure1
Full discourse5 posts
  • William 5hacksphere@w5hacksphere
    General

    The dizzying exercise of trying to wrap my head around the escape in CVE-2025-4517 made WingData an interesting box for me. 16 layers of symlinks just to read the root flag! https://labs.hackthebox.com/achievement/machine/1069235/835

    Post summary

    The user references CVE‑2025‑4517 and shares a personal experience with a symlink escape, but provides no technical, exploit, patch, or active exploitation details.

    0002091
    3 followersView on X
  • ~Ahmed@0xAa0x
    General

    I just solved WingData on Hack The Box! CVE-2025-4517 😎 https://labs.hackthebox.com/achievement/machine/2812972/835 #HackTheBox #HTB #CyberSecurity #EthicalHacking #InfoSec #PenTesting https://t.co/jwu6kXxjiR

    Post summary

    The tweet announces that CVE-2025-4517 was involved in a Hack The Box machine challenge, but no additional technical or exploit details are provided.

    00020155
    181 followersView on X
  • sckull@sckull_
    Disclosure

    HackTheBox - WingData 💥 RCE en Wing FTP Server (CVE-2025-47812) para acceso inicial 🔑 Credenciales para SSH de Wing FTP Server 🚀 Abuso de tarfile (CVE-2025-4517) para escalar privilegios https://sckull.github.io/posts/wingdata/

    Post summary

    The post announces CVE-2025-47812 as an RCE in Wing FTP Server and CVE-2025-4517 as tarfile abuse for privilege escalation, linking to a blog likely containing a PoC, but does not mention active exploitation or patches.

    0000042
    177 followersView on X
  • 1337 Sheets@1337Sheets
    PoC

    Just dropped our WingData 🦅💾 writeup here: https://kzs.m/ajpzyc Dive into the full exploitation chain: 🔹 Recon & Wing FTP Discovery 🔹 Lua Injection RCE (CVE-2025-47812) 🔹 Python Tarfile Filter Bypass (CVE-2025-4517) https://t.co/asLoSPN4ZO

    Post summary

    The post announces a new writeup detailing a full exploitation chain for WingData, including Lua injection RCE (CVE‑2025‑47812) and Tarfile filter bypass (CVE‑2025‑4517), and links to the PoC code.

    0000041
    10 followersView on X
  • BeriwalaRohit@BeriwalaR14274
    Exploit

    WingData: Pwned! 💀🚩 Finally got the root shell on #WingData! The highlight was definitely bypassing Python’s data_filter using the CVE-2025-4517 PATH_MAX overflow logic. 🧠🔥 ✅ 16-level Symlink Tunneling ✅ Realpath resolution bypass https://t.co/qtNolpG53B

    Post summary

    A user reports successfully exploiting CVE-2025-4517 on WingData, achieving a root shell via PATH_MAX overflow and symlink tunneling, but no public PoC or patch is referenced.

    0000038
    2 followersView on X

Explore more