penelope vulnerability

Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall(local_download_folder) on tar archives returned by remote sessions without validating member paths, allowing a malicious or compromised session to write files outside the intended download directory and potentially overwrite ~/.penelope/peneloperc. This issue is fixed in version 0.20.0.

Published 29 Jul 2026Updated 10 Sep 20264 sources
CVSS 5.9

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.