Skip to content

[GHSA-4xh5-x5gv-qwph] pip's fallback tar extraction doesn't check symbolic links point to extraction directory#6358

Merged
advisory-database[bot] merged 1 commit intoichard26/advisory-improvement-6358from
ichard26-GHSA-4xh5-x5gv-qwph
Oct 27, 2025
Merged

[GHSA-4xh5-x5gv-qwph] pip's fallback tar extraction doesn't check symbolic links point to extraction directory#6358
advisory-database[bot] merged 1 commit intoichard26/advisory-improvement-6358from
ichard26-GHSA-4xh5-x5gv-qwph

Commits

Commits on Oct 27, 2025