CVE 8.7 HIGH

GuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCE_CVE-2026-22871

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, there is a path traversal vulnerability exists in GuardDog's safe_extract() function that allows malicious PyPI packages to write arbitrary files outside the intended extraction directory, leading to Arbitrary File Overwrite and Remote Code Execution on systems running GuardDog. This vulnerability is fixed in 2.7.1.

AI Analysis

Path traversal vulnerability in GuardDog's safe_extract() function allows malicious PyPI packages to write arbitrary files outside the intended extraction directory, leading to Arbitrary File Overwrite and Remote Code Execution.

Basic Information

ID CVE-2026-22871
Source GitHub_M
Published Jan 13, 2026 at 20:46
Modified Jan 13, 2026 at 21:24

Affected Product

Vendor DataDog
Product guarddog
Version < 2.7.1
Affected Versions DataDog guarddog < 2.7.1

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor DataDog
Product GuardDog
Version < 2.7.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.