VYPR
Medium severity5.3NVD Advisory· Published Jun 30, 2026· Updated Aug 13, 2026

CVE-2026-4360

CVE-2026-4360

Description

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

19

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.