Skip to content

[GHSA-4xh5-x5gv-qwph] pip's fallback tar extraction doesn't check symbolic links point to extraction directory#6240

Closed
akarve wants to merge 1 commit intoakarve/advisory-improvement-6240from
akarve-GHSA-4xh5-x5gv-qwph
Closed

[GHSA-4xh5-x5gv-qwph] pip's fallback tar extraction doesn't check symbolic links point to extraction directory#6240
akarve wants to merge 1 commit intoakarve/advisory-improvement-6240from
akarve-GHSA-4xh5-x5gv-qwph

Commits

Commits on Sep 30, 2025