CVE-2026-43637 is a path traversal vulnerability in PreferredAI Cornac affecting versions before 2.6.0. The flaw is in the _extract_archive() function in cornac/utils/download.py, where TAR archives are extracted using unsafe handling of archive member paths. A crafted archive containing parent-directory traversal sequences, absolute paths, or symlink or hardlink entries can escape the intended cache directory during extraction. Because Cornac's built-in dataset loaders automatically download and extract archives, a remote attacker who can influence the archive content or source can trigger arbitrary file writes to filesystem locations accessible to the running Cornac process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a README and a single Python PoC exploit. The README documents CVE-2026-43637, a TAR path traversal (Tar Slip) in Cornac versions before 2.6.0, caused by unsafe use of tarfile.extractall() in cornac/utils/download.py without validating member paths. The exploit code is self-contained and reproduces the vulnerable extraction routine, then simulates a Cornac dataset loader that automatically downloads an archive with urllib.request.urlretrieve and extracts it into a cache directory. The PoC's main capability is arbitrary file write outside the intended extraction path by embedding traversal paths in a malicious .tar.gz archive. It starts a local HTTP server on port 8891, serves the crafted archive, and has the simulated loader fetch it over HTTP. The archive includes benign dataset content plus attacker-controlled entries intended to escape the cache directory and overwrite files in a separate victim application tree. The demonstrated impact is configuration tampering and denial of service: settings.cfg is replaced with attacker content and app.py is overwritten so importing it fails. The code also verifies the effect by attempting to load the victim module after exploitation. Structurally, poc_exploit.py includes: constants for the PoC directory/port/archive name; an exact copy of the vulnerable _extract_archive() function; a CornacDatasetLoader class that models the vulnerable download-and-extract flow; helper functions to build the malicious TAR, run an HTTP server, and test module import; and a main() routine that sets up temporary directories representing Cornac and victim scopes, launches the server, triggers exploitation, and prints confirmation output. This is a real exploit PoC rather than a detector, and while it does not provide a shell payload, it operationalizes the arbitrary-write primitive in a reproducible way.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.