{"id":"PYSEC-2026-2440","summary":"dbt-common's commonprefix() doesn't protect against path traversal","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nA path traversal vulnerability exists in dbt-common's `safe_extract()` function used when extracting tarball archives. The function uses `os.path.commonprefix()` to validate that extracted files remain within the intended destination directory. However, `commonprefix()` compares paths character-by-character rather than by path components, allowing a malicious tarball to write files to sibling directories with matching name prefixes.\n\nFor example, when extracting to `/tmp/packages`, a crafted tarball could write files to `/tmp/packagesevil/` by exploiting the character-based prefix matching.\n\nThis vulnerability affects users who:\n- Install dbt packages from untrusted sources\n- Process tarball archives through dbt-common's extraction utilities\n\nThe practical risk is limited because:\n- Exploitation requires a malicious tarball to be processed\n- File writes are restricted to sibling directories with matching prefixes (not arbitrary paths)\n- Packages from trusted sources (dbt Hub) are not affected\n\nThis is similar to CVE-2026-1703 in pip, which had a CVSS score of 3.9 (Low).\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nFixed in `dbt-common` version 1.37.3 & 1.34.2, and patched for dbt-core 1.11.7 and 1.10.20 releases.\n\nThe fix replaces `os.path.commonprefix()` with `os.path.commonpath()`, which correctly compares paths by their components rather than characters.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\n- Only install dbt packages from trusted sources (official dbt Hub, verified git repositories)\n- Avoid installing packages from untrusted URLs or unverified third parties\n- Review package contents before installation when sourcing from external locations\n\n### Resources\n_Are there any links users can visit to find out more?_\n\n1. CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'): https://cwe.mitre.org/data/definitions/22.html\n2. CVE-2026-1703 (similar vulnerability in pip): https://nvd.nist.gov/vuln/detail/CVE-2026-1703\n3. pip fix PR #13777: https://github.com/pypa/pip/pull/13777\n4. Python documentation on `commonpath` vs `commonprefix`: https://docs.python.org/3/library/os.path.html#os.path.commonpath","aliases":["CVE-2026-29790","GHSA-w75w-9qv4-j5xj"],"modified":"2026-07-13T16:31:42.929992505Z","published":"2026-07-13T14:36:40.777932Z","references":[{"type":"WEB","url":"https://github.com/dbt-labs/dbt-common/security/advisories/GHSA-w75w-9qv4-j5xj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-29790"},{"type":"WEB","url":"https://github.com/pypa/pip/pull/13777"},{"type":"WEB","url":"https://github.com/dbt-labs/dbt-common/commit/e547954a48bac9394ef6eb98432e429dce9a7709"},{"type":"WEB","url":"https://docs.python.org/3/library/os.path.html#os.path.commonpath"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6vgw-5pg2-w6jp"},{"type":"PACKAGE","url":"https://github.com/dbt-labs/dbt-common"},{"type":"PACKAGE","url":"https://pypi.org/project/dbt-common"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w75w-9qv4-j5xj"}],"affected":[{"package":{"name":"dbt-common","ecosystem":"PyPI","purl":"pkg:pypi/dbt-common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.34.2"},{"introduced":"1.35.0"},{"fixed":"1.37.3"}]}],"versions":["0.1.0","0.1.0a1","0.1.1","0.1.3","0.1.4","0.1.5","0.1.6","1.0.0","1.0.0b1","1.0.0b2","1.0.1","1.0.2","1.0.3","1.0.4","1.1.0","1.10.0","1.11.0","1.12.0","1.13.0","1.14.0","1.15.0","1.16.0","1.17.0","1.18","1.19","1.2.0","1.20","1.21.0","1.22.0","1.23.0","1.24.0","1.25.0","1.25.1","1.26.0","1.27.0","1.27.1","1.28.0","1.29.0","1.3.0","1.30.0","1.31.0","1.32.0","1.33.0","1.34.0","1.34.1","1.35.0","1.36.0","1.37.0","1.37.1","1.37.2","1.4.0","1.5.0","1.6.0","1.7.0","1.8.0","1.9.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/dbt-common/PYSEC-2026-2440.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}