← Back

CVE-2026-3087

nvd nist
Published: Apr 27, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.0
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: CNA (Secondary)

Description

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

Affected (9)

Products: Python: Python
1 product
Python
Configuration A
9 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Python
Up to 3.14.4
Version 3.15.0 alpha1
Version 3.15.0 alpha2
Version 3.15.0 alpha3
Version 3.15.0 alpha4
Version 3.15.0 alpha5
Version 3.15.0 alpha6
Version 3.15.0 alpha7
Version 3.15.0 alpha8
Running on/withPlatform Versions
Microsoft
Windows
All versions

Timeline

No history available yet.