Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-4138-4517-POC — CVE-2025-4138 / CVE-2025-4517 — Python tarfile PATH_MAX Symlink Filter Bypass | Kitploit
Tools/GitHubGitHub/desertdemons/cve-2025-4138-4517-poc
Privilege EscalationPayload GenerationVulnerability AnalysisExploitationPenetration TestingLearning & EducationBinary Exploitation
GitHubdesertdemons/cve-2025-4138-4517-poc

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-4138-4517-POC

CVE-2025-4138 / CVE-2025-4517 — Python tarfile PATH_MAX Symlink Filter Bypass

View Repository
172163 months agoNot yet reviewed

CVE-2025-4138 CVE-2025-4517 CVSS 9.4 Python Affected

CVE-2025-4138 / CVE-2025-4517
Python tarfile Filter Bypass via PATH_MAX Symlink Escape

Arbitrary file write through filter="data" / filter="tar" extraction

Type CWE-22 Platform Language License Stars Forks Last Commit


Table of Contents

  • Overview
  • Vulnerability Details
  • How It Works
  • Affected Versions
  • Affected Code Pattern
  • Installation
  • Usage
    • Quick Start — SSH Key Injection
    • Preset Attacks
    • Custom Target
  • Proof of Concept — Safe Verification
  • Technical Deep Dive
    • PATH_MAX and os.path.realpath()
    • Symlink Chain Construction
    • Filter Bypass Mechanism
    • Exploitation Stages
  • Real-World Attack Scenarios
  • Detection
  • Mitigation
  • Related CVEs
  • Timeline
  • References
  • Credits
  • Disclaimer
  • License

Overview

A critical vulnerability in Python's tarfile module allows an attacker to bypass extraction filters ("data" and "tar") and write arbitrary files outside the intended extraction directory. When a privileged process (e.g., a root-level backup script, CI/CD pipeline, or package installer) extracts an attacker-controlled tar archive using the supposedly-safe filter="data" parameter, this exploit achieves full arbitrary file write as that privileged user — typically escalating to root.

The root cause is a behavioral quirk in os.path.realpath(): it silently stops resolving symlinks once the fully-expanded path exceeds PATH_MAX (4096 bytes on Linux, 1024 on macOS). The tarfile filter relies on realpath() for safety checks, but the kernel resolves symlinks independently during extraction — creating a TOCTOU (Time-of-Check-to-Time-of-Use) gap that enables directory escape.


Vulnerability Details

FieldValue
CVE IDsCVE-2025-4138, CVE-2025-4517
CVSS v3.19.4 (Critical) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CWECWE-22 — Improper Limitation of a Pathname to a Restricted Directory
Vulnerability TypePath Traversal via Symlink / Filter Bypass
ImpactArbitrary file write → privilege escalation, sandbox escape, data tampering
Attack VectorDeliver malicious tar archive to any application using tarfile.extractall() with filters
AffectedPython 3.12.0 – 3.12.10, 3.13.0 – 3.13.3
Fixed InPython 3.9.23, 3.10.18, 3.11.13, 3.12.11, 3.13.4
PatchCPython PR #135037
AdvisoryGHSA-hgqp-3mmf-7h8f
ReporterCaleb Brown — Google Security Research

How It Works

                    ┌───────────────────────────────────────────┐
                    │         Malicious Tar Structure            │
                    └───────────────────────────────────────────┘

  Stage 1 ── Build symlink chain that inflates the resolved path past PATH_MAX

    ddd...ddd/              (directory, 247 chars)
    a  →  ddd...ddd         (symlink,   1 char name → 247 char dir)
    ddd...ddd/ddd...ddd/    (nested directory)
    b  →  ddd...ddd         (symlink)
    ...  ×16 levels

    Short path (symlinks):   a/b/c/d/e/f/g/h/i/j/k/l/m/n/o/p       ~31 chars
    Resolved path (dirs):    ddd…/ddd…/ddd…/ddd…/ddd…/ddd…/…      ~3968 chars
                                                               ↑ nearing PATH_MAX

  Stage 2 ── Final symlink exceeds PATH_MAX → realpath() stops resolving

    a/b/c/…/p/lll…lll  →  ../../../../../../../../../../../../../../../../..
                            (16 levels of ".." — traverses back to extraction root)

    ┌─────────────────────────────────────────────────────────────────┐
    │  os.path.realpath()  CANNOT expand this  →  filter says "OK" ✓ │
    │  Linux kernel         DOES follow chain  →  actually escapes ✗ │
    └─────────────────────────────────────────────────────────────────┘

  Stage 3 ── Escape symlink resolves to arbitrary filesystem path

    escape  →  <overflow_link>/../../../../../../../root

  Stage 4 ── Create intermediate directories through the escape

    escape/.ssh/            (directory, mode 0700 — created by tar extraction)

  Stage 5 ── Write payload through the escaped symlink

    escape/.ssh/authorized_keys  →  writes to /root/.ssh/authorized_keys  🔓

Affected Versions

Python BranchVulnerable RangeFixed VersionStatus
3.133.13.0 – 3.13.33.13.4✅ Patched
3.123.12.0 – 3.12.103.12.11✅ Patched
3.113.11.4 – 3.11.123.11.13✅ Patched
3.103.10.12 – 3.10.173.10.18✅ Patched
3.93.9.17 – 3.9.223.9.23✅ Patched
3.83.8.17 – 3.8.20—❌ End of Life
3.14+Default filter changed to "data"Check latest⚠️ Higher exposure

Note: Python 3.14+ changed the default filter parameter from no filtering to "data", meaning applications that previously had no filter (and were thus already unsafe) now use the vulnerable filter by default.


Affected Code Pattern

Any application doing this on a vulnerable Python version is exploitable:

import tarfile

# VULNERABLE — filter="data" can be bypassed
with tarfile.open("untrusted_archive.tar", "r") as tar:
    tar.extractall(path="/some/directory", filter="data")

# ALSO VULNERABLE — filter="tar" has the same flaw
with tarfile.open("untrusted_archive.tar", "r") as tar:
    tar.extractall(path="/some/directory", filter="tar")
Download Tool