Python 路径遍历漏洞

情报来源:CNNVD

发布时间:2026-06-23 00:00:00

基本信息
  • 漏洞ID:
  • 漏洞类型:其他
  • 发布日期:2026-06-23 00:00:00
  • 更新时间:2026-06-24 00:00:00
  • CVE编号:CVE-2026-11940
  • CNNVD-ID:CNNVD-2026-98645985
  • 漏洞平台:
  • CVSS评分:
漏洞来源

暂无

漏洞详情

Python Software Foundation CPython是Python Software Foundation基金会的编程语言解释器。 Python存在安全漏洞,该漏洞源于tarfile.extractall()的'data'或'tar'过滤器可被绕过,其中提取回退在硬链接的较浅路径上重新创建了已验证的符号链接,导致相对目标可能逃逸目标目录,使恶意tar存档能创建指向目标外的符号链接,从而造成目录外文件读取或写入。

参考资料

链接:https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f 链接:https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df 链接:https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde 链接:https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c 链接:https://github.com/python/cpython/issues/151558 链接:https://github.com/python/cpython/pull/151559 链接:https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/