← Back to CVE List
Vulnerability Intelligence Report
Arbitrary writes via tarfile realpath overflow

CVE-2025-4517

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.

Path Traversal No Active Exploit Signals
CVSS Base Score
9.4
CRITICAL
Exploitability:3.9
Impact Score:5.5
EPSS Probability:1.28%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Affected Products & Versions

Vendor Product Affected Versions
Python Software Foundation CPython 0 < 3.9.23 (affected), 3.10.0 < 3.10.18 (affected), 3.11.0 < 3.11.13 (affected), 3.12.0 < 3.12.11 (affected), 3.13.0 < 3.13.4 (affected), 3.14.0a1 < 3.14.0b3 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.276%
Vulnerability Class
Path Traversal

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityPython Software Foundation · Vendor · USA
Reserved2025-05-09T15:05:07
Published2025-06-03T12:58:50
Last Updated2026-08-04T14:26:54

LINK COPIED TO CLIPBOARD