CVE-2022-44900 is a critical directory traversal vulnerability affecting the py7zr Python library, specifically versions 0.20.0 and earlier, within its SevenZipFile.extractall() function. This flaw allows unauthenticated attackers to write arbitrary files to a system by extracting a specially crafted 7z archive. With a CVSS score of 9.1 (Critical), the vulnerability is easily exploitable over a network with low complexity and no user interaction, potentially leading to high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, its high EPSS score suggests a significant likelihood of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.20.1CPE matchmatch criteria | cpe:2.3:a:py7zr_project:py7zr:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.