{"id":"CVE-2026-82049","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-82049","summary":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause…","details":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.","published":"2026-09-14T19:17:50.927","modified":"2026-09-14T19:17:50.927","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","label":"python/cpython@5a57248"},"references":[{"type":"WEB","url":"https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca"},{"type":"WEB","url":"https://github.com/python/cpython/issues/157190"},{"type":"WEB","url":"https://github.com/python/cpython/pull/157191"},{"type":"WEB","url":"https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-14T19:17:50.927"}}