Junglewise Threat Intelligence

CVE-2026-88069: Pandora path traversal in archive extraction

CVE-2026-88069 · Severity: info · CVSS 7.5 · Published 2026-09-09

Executive brief

Pandora is a malware analysis platform that processes suspicious files including archives and disk images. A path traversal vulnerability in its archive extraction worker could allow an attacker to write extracted files outside the intended directory, potentially overwriting critical application or system files and causing denial of service or further system compromise.

Technical details

The vulnerability is a path traversal flaw in Pandora's archive extraction worker that fails to validate that extracted file destinations remain within the intended extraction directory. An attacker can submit a specially crafted archive or disk image containing path traversal sequences (e.g., "../../../") in file paths to cause extracted content to be written outside the designated extraction directory. The vulnerability requires an attacker to be able to submit a malicious file for analysis. Successful exploitation could result in unauthorized modification of files accessible to the Pandora worker process, denial of service, or privilege escalation depending on process permissions. The fix validates that resolved extraction destination paths remain below the expected extraction directory and rejects path traversal attempts.

Affected products

  • Pandora Analysis Pandora

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Fix committed to resolve extraction destination paths and verify they remain within the intended directory

References