
Upwind Security MDR@UpwindMDR
🚨High - CPython tarfile Filter Bypass via Hardlink-to-Symlink (CVE-2026-82049) In CPython tarfile.extractall(), extraction filters can be bypassed with a crafted tar containing a hard link targeting a symlink, causing chmod/utime to apply to a file outside the destination dir or exposing its contents via the extracted tree. Non-link entries aren’t affected. 👉Affected: CPython <= 3.13
0000020
303 followersView on X
