
Critical Vulnerability in Python's tarfile Module Allows Arbitrary File Writing
SystemSecurity
A critical vulnerability in the tarfile module of Python's standard library, identified as CVE-2025-4517, allows arbitrary file writing. A proof-of-concept (PoC) exploit has been made public. This security flaw enables an attacker to write arbitrary files on the target system, which can lead to serious consequences such as system compromise or the execution of malicious code.