
Exploit for CVE-2024-6232 - Python Tarfile Realpath Overflow
This script is a weaponized version of the research published in the Google Security Research Advisory: https://github.com/google/security-research/security/advisories/GHSA-hgqp-3mmf-7h8f
While the original research demonstrates the vulnerability by modifying a simple "flag" file, this version is modified for a Local Privilege Escalation (LPE) scenario. Instead of just proving a file can be written outside the extraction directory, this version: