Skip to content

tarfile.data_filter doesn't handle symlinks with empty names #149486

@encukou

Description

@encukou

tarfile.data_filter can be bypassed using a chain of empty-named symlinks (name="").

Linked PRs

Metadata

Metadata

Assignees

Labels

stdlibStandard Library Python modules in the Lib/ directorytype-securityA security issue

Projects

Status

No status

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions