PatchSiren

brightio CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM brightio CVE published 2026-07-29

CVE-2026-50558

Penelope Shell Handler, a post-exploitation shell handler for authorized security testing, had a vulnerability prior to version 0.20.0. The Unix download() implementation in penelope.py used tar.extractall(local_download_folder) on tar archives returned by remote sessions without validating member paths. This allowed a malicious or compromised session to write files outside the intended download directory [truncated]