Junglewise Threat Intelligence

CVE-2026-29509: wummel Patool path traversal in safe_extract

CVE-2026-29509 · Severity: medium · CVSS 5.4 · Published 2026-06-26

Executive brief

Patool is a command-line tool and library used to manage and extract various archive formats. A security flaw allows a malicious archive to trick the software into writing files outside of the intended folder. If an attacker convinces a user to process a specially crafted archive, they could overwrite sensitive system files or plant malicious scripts on the user's computer.

Technical details

A path traversal vulnerability exists in Patool's safe_extract() function within patoolib/programs/py_tarfile.py. The root cause is the is_within_directory() helper function's reliance on os.path.commonprefix() for validation. Because commonprefix() performs character-level rather than path-level string comparison, it can be bypassed by archive member paths that share a prefix with the destination directory but resolve outside of it. This issue specifically affects environments running Python versions prior to 3.12. An attacker can exploit this by providing a crafted archive that, when extracted, writes files to arbitrary locations on the filesystem. The vulnerability is addressed in version 4.0.5.

Affected products

  • wummel Patool < 4.0.5

Timeline

  • 2026-05-18: patched: Version 4.0.5 released
  • 2026-06-26: disclosed: CVE-2026-29509 published

References