{"id":81282,"date":"2026-06-30T18:15:35","date_gmt":"2026-06-30T14:45:35","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2026-4360-tarfile-extract-doesnt-fully-respect-filter-parameter\/"},"modified":"2026-06-30T18:15:35","modified_gmt":"2026-06-30T14:45:35","slug":"cve-2026-4360-tarfile-extract-doesnt-fully-respect-filter-parameter","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2026-4360-tarfile-extract-doesnt-fully-respect-filter-parameter\/","title":{"rendered":"CVE-2026-4360 &#8211; Tarfile.extract() doesn&#8217;t fully respect filter parameter"},"content":{"rendered":"<p>CVE ID :CVE-2026-4360<\/p>\n<p>  Published : June 30, 2026, 2:45 p.m. | 1\u00a0hour ago<\/p>\n<p>  Description :In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid\/gid despite the user passing filter=&#8217;data&#8217; to the extract() function.<\/p>\n<p>  Severity: 2.0 | LOW<\/p>\n<p>  Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID :CVE-2026-4360 Published : June 30, 2026, 2:45 p.m. | 1\u00a0hour ago Description :In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid\/gid despite the user passing filter=&#8217;data&#8217; to the extract() &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-81282","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/81282","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=81282"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/81282\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=81282"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=81282"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=81282"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}