{"type":"bundle","id":"bundle--e8d11c25-f86c-5295-9f18-a7625d7e5bcc","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--f2d4f618-cce7-53cd-8ee5-66e0bb987513","created":"2026-09-20T19:09:26.959Z","modified":"2026-09-20T19:09:26.959Z","name":"Pandora TAR path traversal enables arbitrary file write","description":"Pandora is affected by a TAR path traversal that can enable arbitrary file write. Upgrade to the patched release.","aliases":["CVE-2026-74764"],"first_seen":"2026-08-18T00:00:00.000Z","last_seen":"2026-08-18T12:00:00.000Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"NVD CVE-2026-74764","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74764"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-74764-pandora-tar-path-traversal-arbitrary-file-write"}]}]}