py7zr is vulnerable to Path Traversal
77
High Risk
Affected versions of this package are vulnerable to directory traversal (Zip-Slip) attacks during extraction of archives, where crafted entries with symlinks or paths pointing outside the intended extraction directory could cause files to be written to unexpected locations; this patch enhances path validation by adding stricter checks (including symlink resolution) via is_path_valid and rejects invalid extraction paths, mitigating the Zip-Slip risk.
You are affected if you are using a version that falls within the vulnerable range and if you are using it in a production environment.
py7zr is vulnerable to Path Traversal in versions 0.0.1 - 1.1.1.
Upgrade the py7zr library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant