GHSA-7r27-jhmm-vmp6MediumCVSS 7.5

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a...

Published
April 27, 2026
Last Modified
June 4, 2026

🔗 CVE IDs covered (1)

📋 Description

If shutil.unpack_archive() is given a ZIP archive with an absolute Windows path containing a drive (C:\\...) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

🔗 References (13)