CVE-2026-50558: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in brightio penelope
Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall(local_download_folder) on tar archives returned by remote sessions without validating member paths, allowing a malicious or compromised session to write files outside the intended download directory and potentially overwrite ~/.penelope/peneloperc. This issue is fixed in version 0.20.0.
AI Analysis
Technical Summary
The vulnerability in brightio penelope affects the Unix download() implementation in penelope.py before version 0.20.0. It uses tar.extractall(local_download_folder) on tar archives returned by remote sessions without validating the paths of the archive members. This improper limitation of a pathname to a restricted directory (CWE-22) allows a malicious or compromised session to write files outside the designated download folder, including overwriting ~/.penelope/peneloperc. The vulnerability has a CVSS 3.1 base score of 5.9, indicating medium severity. The issue is resolved in version 0.20.0.
Potential Impact
An attacker controlling a remote session can exploit this vulnerability to write arbitrary files outside the intended download directory, potentially overwriting important configuration files such as ~/.penelope/peneloperc. This can lead to unauthorized modification of the application environment and compromise the integrity of the penelope shell handler.
Mitigation Recommendations
Upgrade to brightio penelope version 0.20.0 or later, where the vulnerability is fixed. Patch status is not explicitly stated in the vendor advisory, but the description confirms the issue is resolved starting with version 0.20.0. Until upgrading, avoid using the vulnerable download() function with untrusted tar archives.
CVE-2026-50558: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in brightio penelope
Description
Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall(local_download_folder) on tar archives returned by remote sessions without validating member paths, allowing a malicious or compromised session to write files outside the intended download directory and potentially overwrite ~/.penelope/peneloperc. This issue is fixed in version 0.20.0.
CVSS v3.1
Score 5.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in brightio penelope affects the Unix download() implementation in penelope.py before version 0.20.0. It uses tar.extractall(local_download_folder) on tar archives returned by remote sessions without validating the paths of the archive members. This improper limitation of a pathname to a restricted directory (CWE-22) allows a malicious or compromised session to write files outside the designated download folder, including overwriting ~/.penelope/peneloperc. The vulnerability has a CVSS 3.1 base score of 5.9, indicating medium severity. The issue is resolved in version 0.20.0.
Potential Impact
An attacker controlling a remote session can exploit this vulnerability to write arbitrary files outside the intended download directory, potentially overwriting important configuration files such as ~/.penelope/peneloperc. This can lead to unauthorized modification of the application environment and compromise the integrity of the penelope shell handler.
Mitigation Recommendations
Upgrade to brightio penelope version 0.20.0 or later, where the vulnerability is fixed. Patch status is not explicitly stated in the vendor advisory, but the description confirms the issue is resolved starting with version 0.20.0. Until upgrading, avoid using the vulnerable download() function with untrusted tar archives.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-04T21:34:34.426Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6a25599c2644c7f8bbd1fc
Added to database: 07/29/2026, 16:07:53 UTC
Last enriched: 07/29/2026, 16:22:54 UTC
Last updated: 07/29/2026, 18:07:54 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.