Path Traversal Vulnerability in Pandora Analysis Tool
CVE-2026-88069
9.3CRITICAL
What is CVE-2026-88069?
Pandora features a path traversal vulnerability within its archive extraction worker. This flaw can be exploited by submitting specially crafted archives or digital images, which could manipulate extraction paths to write files outside the intended directory. Such an exploit could lead to unauthorized changes to critical application or system files, resulting in service disruptions or further compromises depending on the permissions associated with the Pandora process. The vulnerability is mitigated by implementing checks to ensure all extraction paths remain within the expected directory, rejecting any attempts that attempt to traverse outside.
Affected Version(s)
pandora 0 <= 1.12.7
