This issue tracker has been migrated to GitHub, and is currently read-only.
For more information, see the GitHub FAQs in the Python's Developer Guide.

Author eric.araujo
Recipients eric.araujo, leveryd
Date 2021-05-07.20:28:21
SpamBayes Score -1.0
Marked as misclassified Yes
Message-id <1620419301.61.0.0788073965564.issue44023@roundup.psfhosted.org>
In-reply-to
Content
Can you contact the security team (info at https://www.python.org/dev/security/ ) directly?

In general, tarfile (and other Python file functions!) can create files anywhere on the filesystem, provided that the process user has the right permissions.  But it seems that you’re talking about an unexpected behaviour leading to unwanted operations, so please send more details about the problem to the team.  Thank you for your report!
History
Date User Action Args
2021-05-07 20:28:21eric.araujosetrecipients: + eric.araujo, leveryd
2021-05-07 20:28:21eric.araujosetmessageid: <1620419301.61.0.0788073965564.issue44023@roundup.psfhosted.org>
2021-05-07 20:28:21eric.araujolinkissue44023 messages
2021-05-07 20:28:21eric.araujocreate