PT-2026-97204 · Unknown+1 · Buildstream+1

·

CVE-2026-82331

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache BuildStream versions prior to 2.8.1
Description An improper link resolution issue exists in the tar source plugin when running on Python versions prior to 3.12. This allows malicious source tarballs to write files on the host system with the privileges of the user running BuildStream by using symlinks during the source fetching process. Symlinks are symbolic links, which are files that point to another file or directory.
Recommendations Upgrade to version 2.8.1. Use Python version 3.12 or newer. Only use trusted sources in BuildStream projects. Track source tarballs by pinning their SHA256 hash.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82331

Affected Products

Buildstream
Python