Impact
Pandora's TAR archive extraction routine accepts archive member names without sanitization, allowing a crafted TAR file to write files outside the designated extraction directory. This is a classic path traversal flaw (CWE-22) that can overwrite critical files used by the Pandora worker process, potentially leading to application compromise, arbitrary code execution, or denial of service, depending on which files are targeted and the privileges of the process.
Affected Systems
The vulnerability affects Pandora, the forensic analysis tool referenced by the product identifier pandora-analysis:pandora. No specific version information is listed, but the defect is addressed in the repository commit 186b58d41e04248a154d274fffb5813e7fa2012e.
Risk and Exploitability
With a CVSS score of 10 the flaw is considered critical. No EPSS score is available, and it is not yet listed in the CISA KEV catalog. An attacker who can submit a TAR file through any interface that triggers the extraction routine could exploit this weakness remotely. The paucity of blocking controls and the high severity indicate a high likelihood that exploitation could occur in a realistic threat environment.
OpenCVE Enrichment