News

the only mitigation provided being a documentation update warning developers about the risk. The vulnerability is in the Python tarfile package, in code that uses un-sanitized tarfile.extract ...