VYPR

transport

by QBee

CVEs (1)

  • CVE-2026-55828MedSep 15, 2026
    risk 0.32cvss epss 0.00

    qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-disk symlinks created earlier in the extraction process. A crafted tar archive can use a symlink chain…