critical · CVSS v3 9.8 · EPSS 0.00195
CVE-2026-82331
Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildS…
Description
Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python = 3.12, BuildStream >= 2.3.0 already makes use of the Python `tarfile` filter functionality, which blocks the symlink escape Users are recommended to upgrade to version 2.8.1, which fixes this issue.
Scores
- Severity
- critical
- CVSS v2
- 10
- CVSS v3
- 9.8
- CVSS v4
- —
- EPSS
- 0.00195