A vulnerability has been found in brightio penelope up to 0.19.x and classified as critical. This affects the function tar.extractall of the file penelope.py of the component Download. This manipulation causes path traversal.

This vulnerability is registered as CVE-2026-50558. Remote exploitation of the attack is possible. No exploit is available.

The affected component should be upgraded.