← CVEs and Advisories

CVE-2026-63134

cisagov/Malcolm · Severity Medium (CVSS 5.4) · Discovered by Pavan Nallamothu

During archive extraction, directory entries skipped the path guard that file entries passed. Because Python's os.path.join discards every argument before an absolute component, a crafted entry could redirect extraction outside the intended destination.

Summary

Directory traversal in archive extraction (guard/sink mismatch on directory entries).

References

cve.org record · GitHub Security Advisory GHSA-65mm-vgrw-vqx4