techs_targe[verified]@techs44576Disclosure
The report announces three WordPress‑related CVEs, describing their malicious capabilities (arbitrary file upload, directory traversal, and PHP object injection) but does not provide proof of concept, exploit code, or patch information.
Upwind Security MDR[verified]@UpwindMDRPatch
Pandora's TAR extraction flaw (CVE‑2026‑74764) allows path traversal; the advisory recommends upgrading to version 1.12.5 or later where a filter='data' mitigates the issue.
HOL@HashgraphOnlineDisclosure
CVE-2026-74764 is a critical (CVSS 10.0) file‐overwrite vulnerability in the Pandora framework that allows a crafted TAR to escape extraction and overwrite writable files; a PoC link is provided, but no patch or active exploitation is reported.
CVE@CVEnewDisclosure
The entry announces CVE-2026-74764 as a path traversal flaw in Pandora’s TAR extractor, offering basic technical details but no proof of concept, exploit code, or patch information.
CCB Alert@CCBalertDisclosure
The post announces a critical path traversal flaw (CVE-2026-74764) in Pandora with CVSS 10.0, explaining its potential for arbitrary code execution, but offers no PoC, exploit code, or evidence of active exploitation.
SecAlerts@SecAlertsCoPatch
The post alerts to a CVE-2026-74764 path‑traversal flaw in Pandora's TAR extraction with a perfect 10 CVSS score, and notes that a patch is available via the linked commit.
HOL@HashgraphOnlinePatch
The blog notes that Pandora versions up to 1.12.5 are vulnerable to a path‑traversal file‑write via tar.extract(), provides a commit fix (186b58d), and advises patching or blocking uploads until a patched release is available.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The snippet refers to CVE-2026-74764 as a path traversal flaw in Pandora TAR extraction, yet no PoC, exploit, patch, or claim of active exploitation is provided.