All 5 CVE vulnerabilities found in pandora, with AI-generated Chinese analysis, references, and POCs.
Vendor: pandora-analysis
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-88069 | Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis CWE-22 | 9.3 | Critical | 2026-09-09 |
| CVE-2026-75531 | Stored Cross-Site Scripting in URL Observables via Lookyloo Submission Handler in Pandora CWE-79 | 7.0 | High | 2026-08-17 |
| CVE-2026-75529 | Stored Cross-Site Scripting via MIME-Type Confusion in PDF Downloads of Pandora CWE-79 | 6.9 | Medium | 2026-08-17 |
| CVE-2026-74767 | Unbounded DAA Decompression in Pandora Allows Denial of Service via Decompression Bomb CWE-434 | 8.7 | High | 2026-08-15 |
| CVE-2026-74764 | Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandora CWE-22 | 10.0 | Critical | 2026-08-15 |
All 5 known CVE vulnerabilities affecting pandora with full Chinese analysis, references, and POCs where available.