CVE-2025-8917: Python Tarfile Incomplete Symlink Validation
Tarfile extraction incorporates custom member validation (e.g., mitigating CVE-2007-4559) but fails to validate symbolic or hard link targets (`member.linkname`, `member.issym()`, `member.islnk()`). This omission allows path traversal via malicious tarfiles with links pointing outside the intended extraction directory. To fix, validate `linkname` destination
greprules fetch cve-2025-8917-python-tarfile-incomplete-symlink-validation --engine opengrepDescription
Tarfile extraction incorporates custom member validation (e.g., mitigating CVE-2007-4559) but fails to validate symbolic or hard link targets (`member.linkname`, `member.issym()`, `member.islnk()`). This omission allows path traversal via malicious tarfiles with links pointing outside the intended extraction directory. To fix, validate `linkname` destination
Community feedback
0 signals from signed-in users.
- Useful
- 0
- False positive
- 0
- Metadata
- 0