Arbitrary-file-write
2 posts tagged with “Arbitrary-file-write”

cvedb-gptpath-traversal
CVE-2026-80104: DB-GPT Skill Upload Path Traversal (and Sibling CVE-2026-73034)
CVE-2026-80104: v0.8.1 contains the original skill-upload fix, but v0.8.2 regresses it; v0.8.2 fixes sibling CVE-2026-73034
Aug 25, 2026
Read 
cvesecurityvulnerability
BREAKING: CVE-2026-74764 - Pandora TAR Path Traversal Enables Arbitrary File Write
CVE-2026-74764 is a CVSS 10.0 path traversal in Pandora TAR extraction that lets untrusted archives write outside the analysis directory. v1.12.5 is affected; deploy the upstream fix.
Aug 16, 2026
Read