CVE-2026-74764Disclosure

MEDIUMCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names directly to Python's tarfile.TarFile.extract() without applying an extraction filter. An attacker able to submit a specially crafted TAR archive containing malicious member paths, such as paths using ../ sequences or absolute paths, could cause extracted files to be written outside the intended extraction directory. This may allow the attacker to overwrite files accessible to the Pandora worker process and could potentially result in application compromise, arbitrary code execution, or denial of service depending on the files targeted and the privileges of the Pandora process. The vulnerability is corrected by using Python's filter='data' extraction filter, which rejects or sanitizes dangerous TAR members, including paths that escape the destination directory and unsafe link targets. The weakness corresponds to MITRE's general path traversal category, which includes archive extraction cases where attacker-controlled filenames cause files to be written outside the intended directory.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 9 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 4 mentions (2026-08-16); latest day: 1
  • 9 total mentions across 4 days

Deep dive

Activity timeline9 mentions / 4d
01234Mentions · 2026-08-15: 2Mentions · 2026-08-16: 4Mentions · 2026-08-17: 2Mentions · 2026-08-18: 1PoC Mentioned / Linked · 2026-08-16: 1Exploit Tool / Code · 2026-08-16: 1Patch / Workaround · 2026-08-16: 2Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-15: 2Technical Details · 2026-08-16: 4Technical Details · 2026-08-17: 2Technical Details · 2026-08-18: 108-1508-1608-1708-18
Signal classification2 categories
Disclosure
666.7%
Patch
333.3%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-08-152
Disclosure2
2026-08-164
Disclosure2Patch2
2026-08-172
Disclosure2
2026-08-181
Patch1
Full discourse9 posts
  • HOL@HashgraphOnline
    Disclosure

    BREAKING: CVE-2026-74764 is a CVSS 10.0 flaw in Pandora, the file-analysis framework used to inspect suspicious uploads. A crafted TAR can escape the extraction directory with ../ paths or unsafe links and overwrite files writable by the analysis worker. https://t.co/itS2Rkoual

    Post summary

    CVE-2026-74764 is a critical (CVSS 10.0) file‐overwrite vulnerability in the Pandora framework that allows a crafted TAR to escape extraction and overwrite writable files; a PoC link is provided, but no patch or active exploitation is reported.

    10010493
    15.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-74764 Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive mem… https://www.cve.org/CVERecord?id=CVE-2026-74764

    Post summary

    The entry announces CVE-2026-74764 as a path traversal flaw in Pandora’s TAR extractor, offering basic technical details but no proof of concept, exploit code, or patch information.

    001101.7K
    57.9K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical Path Traversal in #Pandora #CVE-2026-74764 CVSS 10.0. An attacker able to submit a crafted TAR archive can overwrite files outside the intended directory, potentially causing application compromise, arbitrary code execution, or denial of service. #Patch #Patch

    Post summary

    The post announces a critical path traversal flaw (CVE-2026-74764) in Pandora with CVSS 10.0, explaining its potential for arbitrary code execution, but offers no PoC, exploit code, or evidence of active exploitation.

    01000327
    7.2K followersView on X
  • techs_targe@techs44576
    Disclosure

    エージェント収集レポート Daily Report 2026.8.17 ■セキュリティ・AI Safety関連 AI Safety 側は新規採用なしで、今日は WordPress とアーカイブ処理の確認が中心です。 ProSolution WP Client CVE-2026-16098 は未認証で任意ファイルをアップロードできる。公開ジョブポータルがあれば更新確認を先に。 https://nvd.nist.gov/vuln/detail/CVE-2026-16098 Pandora CVE-2026-74764 は TAR 展開で抽出先外へファイルを書ける。外部アーカイブの取込経路があれば更新確認を進めたい。 https://nvd.nist.gov/vuln/detail/CVE-2026-74764 ARForms CVE-2024-13784 は 1.8.5 以下の PHP Object Injection。別 plugin / theme の POP chain 併存有無まで確認したい。 https://nvd.nist.gov/vuln/detail/CVE-2024-13784 ■claude code update 由来 上流は静かで、前回の変更を運用へ当てる確認に向いています。 Claude Code の公開差分はなし。最新公開版は v2.1.233 のままです。 https://github.com/anthropics/claude-code/releases/tag/v2.1.233 ■xTECH 由来 今日の本レポートでは、実装人材、悪意なき暴走、信頼性重視 AI が並んでいます。 IT 大手4社が脱・人月へ FDE を拡充。日立は26年度内に国内 FDE 1000人を目指します。 https://xtech.nikkei.com/atcl/nxt/column/18/00001/11956/ OpenAI と Anthropic の評価で実システムへの未承認アクセス事案。自律動作の境界確認が要ります。 https://xtech.nikkei.com/atcl/nxt/column/18/00682/080600214/ KDDI が Buffmee 開始。書籍・雑誌・Webメディアなど約150コンテンツを情報源にしています。 https://xtech.nikkei.com/atcl/nxt/column/18/00086/00416/ オプトの業務改革に生成 AI を投入。「BPR と呼ばない」が成功条件として挙げられています。 https://xtech.nikkei.com/atcl/nxt/column/18/03076/080300029/

    Post summary

    The report announces three WordPress‑related CVEs, describing their malicious capabilities (arbitrary file upload, directory traversal, and PHP object injection) but does not provide proof of concept, exploit code, or patch information.

    00001198
    531 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    📦 Path traversal in Pandora's TAR extraction lets attackers write arbitrary files via crafted archive member names. CVE-2026-74764 scores a perfect 10. Patch via the linked commit now. #cybersecurity #vulnerabilities #ciso #cto #msp https://secalerts.co/vulnerability/CVE-2026-74764?utm_campaign=x https://t.co/DekEj3DbfB

    Post summary

    The post alerts to a CVE-2026-74764 path‑traversal flaw in Pandora's TAR extraction with a perfect 10 CVSS score, and notes that a patch is available via the linked commit.

    0000064
    879 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Pandora TAR Extraction Path Traversal (TarSlip) (CVE-2026-74764) Pandora (CIRCL's file-analysis platform) up to 1.12.5 extracts submitted TAR archives by passing member names straight to Python's tarfile.extract() with no extraction filter. A crafted archive using ../ sequences or absolute paths can write files outside the intended directory. Because Pandora is built to ingest untrusted, attacker-submitted files, this is directly reachable: an attacker can overwrite files the Pandora worker can access, potentially leading to application compromise, arbitrary code execution, or denial of service. The fix adopts Python's filter='data' to reject unsafe members and link targets. 👉Upgrade Pandora past 1.12.5 (fix commit 186b58d), which applies the filter='data' extraction filter.

    Post summary

    Pandora's TAR extraction flaw (CVE‑2026‑74764) allows path traversal; the advisory recommends upgrading to version 1.12.5 or later where a filter='data' mitigates the issue.

    00000105
    292 followersView on X
  • HOL@HashgraphOnline
    Patch

    Pandora <= 1.12.5 is affected. The upstream fix changes tar.extract() to use Python's filter='data'. The latest tagged release is still vulnerable, so deploy a build containing commit 186b58d or block TAR submissions until a patched release ships. https://hol.org/blog/cve-2026-74764-pandora-tar-path-traversal-arbitrary-file-write

    Post summary

    The blog notes that Pandora versions up to 1.12.5 are vulnerable to a path‑traversal file‑write via tar.extract(), provides a commit fix (186b58d), and advises patching or blocking uploads until a patched release is available.

    00000115
    15.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-74764 Path Traversal in Pandora TAR Archive Extraction Allows File Over... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-74764 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The snippet refers to CVE-2026-74764 as a path traversal flaw in Pandora TAR extraction, yet no PoC, exploit, patch, or claim of active exploitation is provided.

    00000139
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-74764 Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive mem… https://www.cve.org/CVERecord?id=CVE-2026-74764 ----- Traducción: CVE-2026-74764 Pan… https://infoflow.cloud`

    Post summary

    New CVE-2026‑74764 disclosed: a path traversal flaw in Pandora’s TAR extraction. No PoC, exploit, or patch details are provided.

    0000033
    98 followersView on X

Explore more