VYPR

BuildStream

by Apache

Source repositories

CVEs (1)

  • CVE-2026-82331CriSep 23, 2026
    risk 0.57cvss 9.8epss 0.00

    Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the user running BuildStream, via symlinks…