
CVE-2026-3087: CPython: shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs https://www.openwall.com/lists/oss-security/2026/04/28/9 ZIP archive with an absolute path containing a drive (`C:\\...`) may be extracted outside the target directory on Windows
Post summary
The post discloses a path traversal flaw in CPython’s shutil.unpack_archive, where ZIP archives containing Windows absolute paths can extract files outside the intended directory.
