Title: shutil.unpack_archive(): security concerns not documented
Author: Jakub Wilk (jwilk) Date: 2014-02-23 21:13
shutil.unpack_archive() uses tarfile.extractall() under the hood, so it's not suitable for unpacking untrusted archives. But this fact is not documented.

Please add a security warning to shutil.unpack_archive() documentation.
Author: Mark Lawrence (BreamoreBoy) Date: 2015-05-03 06:50
If there is an agreed standard for security warnings I'll prepare a patch for this.
