Skip to content

0.3.45 — Security fix for sandbox archive extraction

Latest

Choose a tag to compare

@vndee vndee released this 28 Sep 04:30
eecb916

Security fix

Fixes unsafe host-side archive extraction in copy_from_runtime() described in GHSA-crfw-xvcm-hjxj.

  • Apply tarfile.data_filter explicitly to sanitize archive permissions and ownership on every supported Python version.
  • Reject FIFOs, device nodes, and unsupported member types before writing archive contents.
  • Retain existing link/path exclusions and reject extraction targets that escape the destination.
  • Fail safely when the Python installation lacks the data filter instead of falling back to unrestricted extraction.

Upgrade

python -m pip install --upgrade 'llm-sandbox>=0.3.45'

Keep your existing backend extras when upgrading, for example llm-sandbox[docker]>=0.3.45.

Python 3.10/3.11 installations must include the backported tarfile.data_filter; update Python if extraction reports that safe filtering is unavailable. Python 3.12+ provides the filter. Use a fresh output directory protected from untrusted writers.

Validation

Added 19 security regression cases. Local verification passed the full suite (1,313 passed, two optional tests skipped), focused extraction checks on Python 3.10–3.14, static checks, and the documentation build.

Thanks to @screeck for the report and proof of concept.

Fix: #221