CVE-2026-74764: Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandora

Published Aug 15, 2026
·
Updated

Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names directly to Python's tarfile.TarFile.extract() without applying an extraction filter.

An attacker able to submit a specially crafted TAR archive containing malicious member paths, such as paths using ../ sequences or absolute paths, could cause extracted files to be written outside the intended extraction directory. This may allow the attacker to overwrite files accessible to the Pandora worker process and could potentially result in application compromise, arbitrary code execution, or denial of service depending on the files targeted and the privileges of the Pandora process.

The vulnerability is corrected by using Python's filter='data' extraction filter, which rejects or sanitizes dangerous TAR members, including paths that escape the destination directory and unsafe link targets.

The weakness corresponds to MITRE's general path traversal category, which includes archive extraction cases where attacker-controlled filenames cause files to be written outside the intended directory.

Affected Software

1 affected component
OpenAI Pandora

Event History

Aug 15, 2026
CVE Published
via MITRE·09:39 PM
Data Sourced
via MITRE·09:39 PM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-74764?

The severity of CVE-2026-74764 is rated as 65.

2

How do I fix CVE-2026-74764?

To fix CVE-2026-74764, ensure that the TAR archive extractor applies proper validation and filtering on archive member names.

3

What type of vulnerability is CVE-2026-74764?

CVE-2026-74764 is categorized as a path traversal vulnerability.

4

What can an attacker do with CVE-2026-74764?

An attacker can exploit CVE-2026-74764 to perform arbitrary file writes by submitting a specially crafted TAR archive.

5

In which software is CVE-2026-74764 found?

CVE-2026-74764 is found in OpenAI Pandora.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203