HackTesting
HomeArticlesTagsContact

CVE-2026-3087

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

Credits

Serhiy Storchaka (https://github.com/serhiy-storchaka)
Seth Larson (https://github.com/sethmlarson)
GGAutomaton (https://github.com/GGAutomaton)

References

https://github.com/python/cpython/pull/146591
https://github.com/python/cpython/issues/146581
https://mail.python.org/archives/list/security-announce@python.org/thread/X6FXE5C6KDKOVNX3EC3DWD5RUPFWOZA4/
https://github.com/python/cpython/commit/ab5ef98af693bded74a738570e81ea70abef2840
https://github.com/python/cpython/commit/b01e594fbe754a960212f908d047294e880b52fd
https://github.com/python/cpython/commit/fc829e88753858c8ac669594bf0093f44948c0f4
https://github.com/python/cpython/commit/65b255416ae217bf0e22085be3c1976cea18bd8c
https://github.com/python/cpython/commit/8e13025747e1ca72e86d1f35637123f9c306f0cb
https://github.com/python/cpython/commit/8ee6aff14054b37b53e47194a2fa313e98163c94
https://github.com/python/cpython/commit/ba0aca3bffce431fe2fbd53ca4cd6a717a2e2c19
https://github.com/python/cpython/commit/a6650a2cdf0c49fb8ce0c982903aa2aa274beefe
https://github.com/python/cpython/commit/7ef7dd0a74f47facd1fadcbc77f8fb03beb5eb4d
Published
Apr 27, 2026 20:46:43 UTC
Updated
Aug 10, 2026 00:23:57 UTC
Reserved
Feb 23, 2026 23:14:46 UTC
  • Home
  • Contact Us
  • Recently Updated CVEs
  • Articles
  • Tags
  • RSS Feed
  • Privacy Policy
© 2026 HackTesting. All rights reserved.