Improper Link Resolution Vulnerability in Apache BuildStream Source Plugin
CVE-2026-82331
Currently unrated
What is CVE-2026-82331?
A vulnerability exists in the 'tar' source plugin of Apache BuildStream, enabling malicious source tarballs to exploit improper link resolution, potentially writing files on the host system. This occurs when symlinks are used in source fetching, leading the user executing BuildStream to inadvertently allow unauthorized file access. While the issue can be mitigated by only using trusted sources, the recommended action is to upgrade to BuildStream version 2.8.1 to eliminate this vulnerability entirely. Ensure you are using Python version 3.12 or higher for added protection, as newer versions leverage the Python tarfile filter functionality to prevent symlink escapes.
Affected Version(s)
Apache BuildStream 0 <= 2.8.0
Apache BuildStream 2.8.1