Warning: Multiple vulnerabilities in CPython lead to arbitrary writes, file permission modification, and more. Patch Immediately!
ID: 39cc6e04-2054-5d98-967f-ab5589c814dd
STIX ID: report--39cc6e04-2054-5d98-967f-ab5589c814dd
**Executive summary:** Multiple critical vulnerabilities in CPython's TarFile.extractall()/extract() (including CVE-2025-4517 and others) can allow attackers to bypass extraction safety checks, perform path traversal and arbitrary file writes outside intended directories, create or exploit symlinks, and modify file metadata or permissions; affected Python versions span 3.10 through 3.14 (specific patch ranges provided), and the Centre for Cybersecurity Belgium recommends prioritizing updates and enhancing detection despite no confirmed active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
