7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
CVE-2025-4138 — Python tarfile filter="data" Bypass Arbitrary file write outside the extraction directory via PATHMAX symlink chain. Affected Versions - Python 3.12.0 – 3.12.10 - Python 3.13.0 – 3.13.3 - Fixed in 3.12.11 / 3.13.4 Credit: Reporter:...
Basic Information
ID
5082A5F9-2C69-5B9A-9CC3-86969E9C2A4A
Published
Feb 15, 2026 at 21:59
Modified
Feb 15, 2026 at 22:00