Executive brief
Patool is a command-line tool and library used to manage and extract various archive formats. A security flaw allows a malicious archive to trick the software into writing files outside of the intended folder. If an attacker convinces a user to process a specially crafted archive, they could overwrite sensitive system files or plant malicious scripts on the user's computer.
Technical details
A path traversal vulnerability exists in Patool's safe_extract() function within patoolib/programs/py_tarfile.py. The root cause is the is_within_directory() helper function's reliance on os.path.commonprefix() for validation. Because commonprefix() performs character-level rather than path-level string comparison, it can be bypassed by archive member paths that share a prefix with the destination directory but resolve outside of it. This issue specifically affects environments running Python versions prior to 3.12. An attacker can exploit this by providing a crafted archive that, when extracted, writes files to arbitrary locations on the filesystem. The vulnerability is addressed in version 4.0.5.
Affected products
- wummel Patool < 4.0.5
Timeline
- 2026-05-18: patched: Version 4.0.5 released
- 2026-06-26: disclosed: CVE-2026-29509 published