CVE-2026-3087
If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th
If shutil.unpack_archive() is given a ZIP archive with an absolute Windows path containing a drive (C:\\...) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.
HIGH · CVSS 7.5
EPSS 0.00078
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules15
YARA rules0