highCVSS 8.8New
October 1, 2026
Arbitrary file write on the client host via archive auto-unpacking and recursive downloads
GHSA-cc42-7jx5-834x
Patched in: v7.26.3
Read the advisory
Security
If you believe you have found a security issue in Pelican, please email security@pelicanplatform.org rather than opening a public issue. See the security policy for what to include in a report.
Patched in: v7.26.3
Patched in: 7.26.1
Patched in: 7.26.1
Patched in: 7.26.1
Patched in: v7.21.5, v7.22.3, v7.23.3, v7.24.2