Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-4330

24
FAUCET Score

CVE-2025-4330 is a path traversal vulnerability in the Python tarfile module, affecting applications that extract untrusted tar archives using TarFile.extractall() or TarFile.extract() with the "data" or "tar" filter. This allows attackers to write files outside the intended directory and modify file metadata. Rated 7.5 HIGH on CVSS, it has a network attack vector and high impact on integrity, though no active exploitation, public exploit code, or significant community discussion has been observed.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 3.10.18CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.11.0, < 3.11.13CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.12.0, < 3.12.11CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.13.0, < 3.13.4CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.80%
Probability of exploitation in next 30 days
EPSS Percentile
53.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0080 is in the 28th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (26)

microsoftpatch availablevia msrc
Product: 19533-16823Fixed in: 3.9.19-14
microsoftpatch availablevia msrc
Product: 19681-17086Fixed in: 3.9.19-14
microsoftpatch availablevia msrc
Product: 17604-17084Fixed in: 3.12.9-2
microsoftpatch availablevia msrc
Product: cbl2 python3 3.9.19-14 on CBL Mariner 2.0Fixed in: 3.9.19-14
microsoftpatch availablevia msrc
Product: cbl2 python3 3.9.19-13 on CBL Mariner 2.0Fixed in: 3.9.19-14
microsoftpatch availablevia msrc
Product: azl3 python3 3.12.9-1 on Azure Linux 3.0Fixed in: 3.12.9-2
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: python3-0:3.6.8-47.el8_6.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnFixed in: python3-0:3.6.8-47.el8_6.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: python3-0:3.6.8-47.el8_6.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: python3-0:3.6.8-47.el8_6.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update Support Long-Life Add-OnFixed in: python3-0:3.6.8-51.el8_8.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: python3-0:3.6.8-51.el8_8.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: python3-0:3.6.8-51.el8_8.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: python3.12-0:3.12.9-2.el10_0.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.11-0:3.11.11-2.el9_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.12-0:3.12.9-1.el9_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: python3.12-0:3.12.1-4.el9_4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: python3.9-0:3.9.18-3.el9_4.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: python3.11-0:3.11.7-1.el9_4.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-server-rhel9:sha256:c517869dacaf4d3650310d4a52e83706e0b311d6ebb4a9b37b1c7acff5c142ec
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.9-0:3.9.21-2.el9_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3.11-0:3.11.13-1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3.12-0:3.12.11-1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39:3.9-8100020251126112422.d47b87a4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39-devel:3.9-8100020251126112422.d47b87a4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3-0:3.6.8-70.el8_10
View patch

Vendor Advisories (2)

microsoft2025-Jun/CVE-2025-4330Important

Extraction filter bypass for linking outside extraction directory

Jun 10, 2025
redhatCVE-2025-4330Moderate

cpython: python: Extraction filter bypass for linking outside extraction directory

Jun 3, 2025

References

gist.github.com / sethmlarson/52398e33eff261329a0180ac1d54f42f
github.com / python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da
github.com / python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9
github.com / python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a
github.com / python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e
github.com / python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a
github.com / python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a
github.com / python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01
github.com / python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1
github.com / python/cpython/issues/135034
github.com / python/cpython/pull/135037
mail.python.org / archives/list/[email protected]/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG