py7zr is vulnerable to Path Traversal
77
High Risk
Affected versions of this package are vulnerable to directory traversal (Zip-Slip) attacks during extraction of archives, where crafted entries with symlinks or paths pointing outside the intended extraction directory could cause files to be written to unexpected locations; this patch enhances path validation by adding stricter checks (including symlink resolution) via is_path_valid and rejects invalid extraction paths, mitigating the Zip-Slip risk.
You are affected if you are using a version that falls within the vulnerable range and if you are using it in a production environment.
py7zr is vulnerable to Path Traversal in versions 0.0.1 - 1.1.1.
Upgrade the py7zr library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant