What is CVE-2026-50558?
CVE-2026-50558: In Penelope Shell Handler versions prior to 0.20.0, the Unix `download()` implementation in `penelope.py` extracts tar archives from remote sessions without validating member paths, leading to a path traversal vulnerability. This allows a malicious remote session to perform unauthorized file writes. Users must upgrade to version 0.20.0 immediately.
Azərbaycanca: CVE-2026-50558: Penelope Shell Handler-in 0.20.0 versiyasından əvvəlki versiyalarında, `penelope.py` faylındakı `download()` funksiyası uzaq seanslardan alınan tar arxivlərini yoxlamadan çıxarır. Bu, "path traversal" boşluğuna səbəb olaraq zərərli sessiyaya fayl sisteminə icazəsiz faylları yazmaq imkanı verir. İstifadəçilər dərhal 0.20.0 versiyasına yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of Penelope Shell Handler are affected by CVE-2026-50558?
All versions prior to 0.20.0 are affected. Users must upgrade to version 0.20.0 immediately.
What can an attacker achieve by exploiting CVE-2026-50558?
An attacker can perform unauthorized file writes to the file system through a malicious remote session by exploiting the path traversal vulnerability in the `download()` function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.