CVE-2026-58198: Tarfile Unsafe Extraction Symlink Bypasscve-2026-58198-tarfile-unsafe-extraction-symlink-bypass
Extraction of tar files using a path traversal check that utilizes `os.path.abspath` instead of `os.path.realpath`, or iterates over members without checking for symbolic links (`issym()` or `islnk()`), allows attackers to bypass path traversal protections. An attacker can craft a malicious tar file with symlinks that point outside the target directory, lead