Product
The patool library prior to version 4.0.6 contains an OS command injection vulnerability on Windows that allows arbitrary command execution via crafted archive filenames.