VYPR

tar source plugin

by Apache BuildStream

CVEs (1)

  • CVE-2026-82331Sep 23, 2026
    risk 0.00cvss epss

    Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the user running BuildStream, via symlinks…

VYPR — Vulnerability Intelligence