CVE-2026-23879
Last modified
CVE-2026-23879 is a high-severity vulnerability rated 8/10 on the CVSS scale. py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreated outside the destination directory via crafted malicious symbolic link chains. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreated outside the destination directory via crafted malicious symbolic link chains. When using extractall to extract an archive, the library restores these symbolic links, linking them to arbitrary directories on the host file system. During extraction, the program only checks the link arcname within the destination directory, but ignores the combined symlink path resolution. Attackers can exploit this vulnerability by constructing malicious archives, thereby bypassing the directory boundary restrictions implemented by the extractor. Subsequent extraction of regular files through these symbolic links can result in arbitrary file writes. This vulnerability may lead to remote code execution, privilege escalation, data corruption, or denial of service. This issue has been fixed in version 1.1.3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-23879?
How severe is CVE-2026-23879?
How do I fix CVE-2026-23879?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-23873hustoj is an open source online judge based on PHP/C++/MySQL…9
- CVE-2026-23874ImageMagick is free and open-source software used for editin…5.5
- CVE-2026-23875CrawlChat is an open-source, AI-powered platform that transf…5.4
- CVE-2026-23876ImageMagick is free and open-source software used for editin…9.8
- CVE-2026-23877Swing Music is a self-hosted music player for local audio fi…4.3
- CVE-2026-23878HotCRP is conference review software. Starting in commit aa2…6.5
- CVE-2026-23880OnboardLite is a comprehensive membership lifecycle platform…7.3
- CVE-2026-23881Kyverno is a policy engine designed for cloud native platfor…6.5
- CVE-2026-23882Blinko is an AI-powered card note-taking project. Prior to v…7.2
- CVE-2026-23883FreeRDP is a free implementation of the Remote Desktop Proto…9.8
- CVE-2026-23884FreeRDP is a free implementation of the Remote Desktop Proto…9.8
- CVE-2026-23885Alchemy is an open source content management system engine w…9.9
Are you affected by CVE-2026-23879?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
