HIGH8.8
PYSEC-2026-1848
python-libarchive directory traversal
Details
python-libarchive through 4.2.1 allows directory traversal (to create files) in extract in zip.py for ZipFile.extractall and ZipFile.extract.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/python-libarchive
Introduced in:
0No fixed version published yet for python-libarchive (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-55587[ADVISORY]
- https://github.com/smartfile/python-libarchive/issues/42[WEB]
- https://github.com/smartfile/python-libarchive/pull/41[WEB]
- https://github.com/smartfile/python-libarchive[PACKAGE]
- https://github.com/smartfile/python-libarchive/blob/c7677411bfc4ab5701d343bc6ebd9e35c990e80e/libarchive/zip.py#L107[WEB]
- https://pypi.org/project/python-libarchive[PACKAGE]
- https://github.com/advisories/GHSA-75mx-hw5q-pvx3[ADVISORY]