This issue tracker has been migrated to GitHub, and is currently read-only.
For more information, see the GitHub FAQs in the Python's Developer Guide.

Author jwilk
Recipients docs@python, jwilk
Date 2014-02-23.21:13:37
SpamBayes Score -1.0
Marked as misclassified Yes
Message-id <>
shutil.unpack_archive() uses tarfile.extractall() under the hood, so it's not suitable for unpacking untrusted archives. But this fact is not documented.

Please add a security warning to shutil.unpack_archive() documentation.
Date User Action Args
2014-02-23 21:13:37jwilksetrecipients: + jwilk, docs@python
2014-02-23 21:13:37jwilksetmessageid: <>
2014-02-23 21:13:37jwilklinkissue20749 messages
2014-02-23 21:13:37jwilkcreate