OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-82331

CRITICAL · CVSS 9.8 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects the `tar` source plugin in Apache BuildStream versions running on Python prior to 3.12, allowing malicious source tarballs to exploit symlinks and write files on the host system with the privileges of the user executing BuildStream. This could lead to unauthorized file access and potential system compromise if untrusted sources are used. Users of affected versions should prioritize upgrading to version 2.8.1 to mitigate this risk, especially if they are handling unverified source tarballs.

CVE
CVE-2026-82331
Severity
CRITICAL
CVSS
9.8
EPSS
0.42%
Apache

Original NVD Description

Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the user running BuildStream, via symlinks as part of source fetching. The impact of this issue is mitigated by: * BuildStream projects should only use trusted sources in their elements as otherwise the build output can also not be trusted * Tracking a source tarball pins its SHA256 hash, which prevents MITM attacks of users that are fetching an already tracked project * When running on Python >= 3.12, BuildStream >= 2.3.0 already makes use of the Python `tarfile` filter functionality, which blocks the symlink escape Users are recommended to upgrade to version 2.8.1, which fixes this issue.