A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.
"https://github.com/pypa/advisory-database/blob/main/vulns/py7zr/PYSEC-2022-42998.yaml"