VYPR

penelope

by Brightio

CVEs (1)

  • CVE-2026-50558Jul 29, 2026
    risk 0.00cvss epss 0.00

    Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall(local_download_folder) on tar archives returned by remote sessions without validating member paths,…