CVE-2026-58198: Tarfile Unsafe Extraction Symlink Bypass

Extraction of tar files using a path traversal check that utilizes `os.path.abspath` instead of `os.path.realpath`, or iterates over members without checking for symbolic links (`issym()` or `islnk()`), allows attackers to bypass path traversal protections. An attacker can craft a malicious tar file with symlinks that point outside the target directory, lead

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-58198-tarfile-unsafe-extraction-symlink-bypass --engine opengrep

Description

Extraction of tar files using a path traversal check that utilizes `os.path.abspath` instead of `os.path.realpath`, or iterates over members without checking for symbolic links (`issym()` or `islnk()`), allows attackers to bypass path traversal protections. An attacker can craft a malicious tar file with symlinks that point outside the target directory, lead