HIGHPyPI →
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
Affected packages
- penelope-shell-handler— before 0.20.0
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- 0.25%
- EPSS percentile
- 16.4%
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 16%.
Sources
- https://github.com/brightio/penelope/security/advisories/GHSA-f42x-p2mx-hm8r
- https://github.com/brightio/penelope/commit/a040afb5db32c7e80b5e8a2f9b2164cf911cfa62
- https://github.com/brightio/penelope
- https://github.com/brightio/penelope/releases/tag/v0.20.0
Structured record: https://osv.dev/vulnerability/GHSA-f42x-p2mx-hm8r
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta