python has a historical issue with tarfile extraction wrt paths a pr was originally raised in envoy here https://github.com/envoyproxy/envoy/pull/23530 this is a low priority issue which is unlikely to be exploitable but keeping a record here