PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-82049 Python Software Foundation CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-14T19:17:50.927Z and has not been modified since then. The vulnerability in CPython's tarfile module allows crafted archives to modify file permissions or expose contents outside the destination directory. Defenders should verify archive integrity and update the tarfile module. The CVE details indicate a HIGH severity with a CVSS score of 8.4, emphasizing the need for prompt assessment and mitigation.

Vendor
Python Software Foundation
Product
CPython
CVSS
HIGH 8.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-14
Original CVE updated
2026-09-30
Advisory published
2026-09-14
Advisory updated
2026-09-30

Who should care

Defenders responsible for CPython deployments, particularly those using the tarfile module, should assess their exposure and verify the integrity of extracted archives. This includes reviewing current CPython versions, identifying potential vulnerabilities, and implementing necessary updates or mitigations. Security teams and operators must prioritize verifying the presence of CPython 3.13 or earlier in their environments and assess the exposure of such CP

Why it matters

Defenders should prioritize verifying the presence of CPython 3.13 or earlier in their environments and assess the exposure of archives containing crafted hard links to symbolic links. The vulnerability in the tarfile module may cause extraction to modify file permissions or modification times outside the destination directory, or expose file contents within the extracted tree. Verification of archive integrity and tarfile module updates is required.

  • Potential modification of file permissions or modification times outside the destination directory
  • Potential exposure of file contents within the extracted tree
  • Verification of archive integrity and tarfile module updates required
  • Assessment of CPython 3.13 or earlier presence in the environment

Technical summary

The tarfile module in CPython 3.13 and earlier is vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree. This vulnerability can lead to unintended changes in file permissions or modification times, and potentially expose sensitive information. The affected module does not properly handle hard links to symbolic links, allowing attackers to manipulate files outside the intended extraction directory.

Defensive priority

Defenders should prioritize verifying the presence of CPython 3.13 or earlier in their environments and assess the exposure of archives containing crafted hard links to symbolic links.

Recommended defensive actions

  • Verify the presence of CPython 3.13 or earlier in your environment
  • Assess the exposure of archives containing crafted hard links to symbolic links
  • Review and update the tarfile module to the latest version
  • Implement compensating controls for exposed systems
  • Monitor relevant logs for exposed assets
  • Track exceptions and retest remediated assets
  • Review vendor patch guidance for CPython updates

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in CPython's tarfile module. However, the corpus does not establish versions, exploitation, impact, or remediation for specific systems or deployments.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-82049 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-82049

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-82049 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82049

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.