Symlink Attack Affecting py7zr package, versions [,1.1.3)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.4% (33rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-PY7ZR-17391447
  • published21 Jun 2026
  • disclosed19 Jun 2026
  • creditHughLewis20

Introduced: 19 Jun 2026

CVE-2026-23879  (opens in a new tab)
CWE-59  (opens in a new tab)

How to fix?

Upgrade py7zr to version 1.1.3 or higher.

Overview

py7zr is a Pure python 7-zip library

Affected versions of this package are vulnerable to Symlink Attack in the extractall method. An attacker can overwrite arbitrary files on the host system by crafting malicious archives containing symbolic link chains that escape the intended extraction directory. This can result in remote code execution, privilege escalation, data corruption, or denial of service.

CVSS Base Scores

version 4.0
version 3.1