SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-74764

CRITICAL · CVSS 10 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Pandora's TAR archive extraction functionality is vulnerable to a path traversal attack, allowing an attacker to craft a malicious TAR archive that can extract files outside the designated directory. This could lead to file overwrites, application compromise, arbitrary code execution, or denial of service, depending on the targeted files and the privileges of the Pandora process. Organizations using Pandora should prioritize patching this critical vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-74764
Severity
CRITICAL
CVSS
10
EPSS
0.40%

Original NVD Description

Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names directly to Python's tarfile.TarFile.extract() without applying an extraction filter. An attacker able to submit a specially crafted TAR archive containing malicious member paths, such as paths using ../ sequences or absolute paths, could cause extracted files to be written outside the intended extraction directory. This may allow the attacker to overwrite files accessible to the Pandora worker process and could potentially result in application compromise, arbitrary code execution, or denial of service depending on the files targeted and the privileges of the Pandora process. The vulnerability is corrected by using Python's filter='data' extraction filter, which rejects or sanitizes dangerous TAR members, including paths that escape the destination directory and unsafe link targets. The weakness corresponds to MITRE's general path traversal category, which includes archive extraction cases where attacker-controlled filenames cause files to be written outside the intended directory.