GHSA-m8xw-9x5x-6vh3
CRITICALCVE-2022-44900A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.
- Affected
- <= 0.20.0
- Fixed in
- 0.20.1
- Published
- 2022-12-06
- Source
- github