Security Fixes
- Path Traversal in TAR Archive Extraction Allows Arbitrary File Write - GHSA-wc2q-m7w7-fj3m - https://vulnerability.circl.lu/vuln/gcve-1-2026-20162
- Unbounded DAA Decompression in Pandora Allows Denial of Service via Decompression Bomb - GHSA-rm3q-48hj-2jvm - https://vulnerability.circl.lu/vuln/gcve-1-2026-20014
- Stored Cross-Site Scripting via MIME-Type Confusion in PDF Downloads of Pandora - GHSA-4wr3-42mx-gxw6 - https://vulnerability.circl.lu/vuln/gcve-1-2026-20132
- Stored Cross-Site Scripting in URL Observables via Lookyloo Submission Handler in Pandora - GHSA-p3mg-r3gg-4h7r - https://vulnerability.circl.lu/vuln/gcve-1-2026-20049
Thank you @Wachizungu for the reports!
What's Changed
- build(deps): bump github/codeql-action from 4.37.3 to 4.37.4 by @dependabot[bot] in #984
- build(deps): bump docker/login-action from 4.5.2 to 4.6.0 by @dependabot[bot] in #985
- build(deps): bump github/codeql-action from 4.37.4 to 4.37.6 by @dependabot[bot] in #991
Full Changelog: v1.12.5...v1.12.6