VYPR

transport

by QBee

CVEs (1)

  • CVE-2026-55828Jun 19, 2026
    risk 0.00cvss epss

    ### Impact The go.qbee.io/transport library is affected by a symlink-chain path traversal vulnerability in its extractTar routine. The library's path validation is strictly lexical and fails to account for on-disk symlinks created earlier in the extraction process.…