CVE Explorer
CVE-2026-23879
py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreated outside the destination directory via crafted malicious symbolic link chains. When using extractall to extract an archive, the library restores these symbolic links, linking them to arbitrary directories on the host file system. During extraction, the progra
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"py7zr","vendor":"miurahr","versions":[{"status":"affected","version":"< 1.1.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e0c71726ec64808a848dab5639dbcc54bb1d4b5f29a511d766bda92ae49f97ee · sha256:0867128a9daa937d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e0c71726ec64808a848dab5639dbcc54bb1d4b5f29a511d766bda92ae49f97ee · sha256:0867128a9daa937d… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-59","description":"CWE-59: Improper Link Resolution Before File Access ('Link Following')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e0c71726ec64808a848dab5639dbcc54bb1d4b5f29a511d766bda92ae49f97ee · sha256:0867128a9daa937d… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/miurahr/py7zr/releases/tag/v1.1.3","tags":["x_refsource_MISC"],"url":"https://github.com/miurahr/py7zr/releases/tag/v1.1.3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e0c71726ec64808a848dab5639dbcc54bb1d4b5f29a511d766bda92ae49f97ee · sha256:0867128a9daa937d… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/miurahr/py7zr/security/advisories/GHSA-q6rc-2cgv-63h7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e0c71726ec64808a848dab5639dbcc54bb1d4b5f29a511d766bda92ae49f97ee · sha256:0867128a9daa937d… · /containers/adp/0/references/0
{"name":"https://github.com/miurahr/py7zr/security/advisories/GHSA-q6rc-2cgv-63h7","tags":["x_refsource_CONFIRM"],"url":"https://github.com/miurahr/py7zr/security/advisories/GHSA-q6rc-2cgv-63h7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e0c71726ec64808a848dab5639dbcc54bb1d4b5f29a511d766bda92ae49f97ee · sha256:0867128a9daa937d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.