CVE-2026-82331: CWE-59 Improper link resolution before file access ('link following') in Apache Software Foundation Apache BuildStream
Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the user running BuildStream, via symlinks as part of source fetching. The impact of this issue is mitigated by: * BuildStream projects should only use trusted sources in their elements as otherwise the build output can also not be trusted * Tracking a source tarball pins its SHA256 hash, which prevents MITM attacks of users that are fetching an already tracked project * When running on Python >= 3.12, BuildStream >= 2.3.0 already makes use of the Python `tarfile` filter functionality, which blocks the symlink escape Users are recommended to upgrade to version 2.8.1, which fixes this issue.
AI Analysis
Technical Summary
Apache BuildStream versions up to 2.8.0 running on Python versions below 3.12 have an improper link resolution vulnerability (CWE-59) in the tar source plugin. This flaw allows malicious tarballs to exploit symlink following to write files on the host system with the privileges of the BuildStream user during source fetching. Mitigations include using trusted sources, SHA256 hash pinning to prevent MITM attacks, and the use of Python 3.12's tarfile filter functionality in BuildStream 2.3.0 and later, which blocks symlink escapes. The issue is resolved in BuildStream version 2.8.1.
Potential Impact
An attacker controlling a malicious source tarball can write arbitrary files on the host system with the privileges of the user running BuildStream. This could lead to unauthorized file modifications or code execution within the context of the BuildStream user. However, the impact is mitigated if only trusted sources are used, source tarballs are pinned by SHA256 hashes, or if running on Python 3.12 or later with BuildStream 2.3.0 or newer.
Mitigation Recommendations
Users should upgrade to Apache BuildStream version 2.8.1, which fixes this vulnerability. Additionally, ensure that only trusted sources are used for BuildStream elements and that source tarballs are pinned by SHA256 hashes to prevent MITM attacks. Running BuildStream on Python 3.12 or later also mitigates this issue due to improved tarfile handling.
CVE-2026-82331: CWE-59 Improper link resolution before file access ('link following') in Apache Software Foundation Apache BuildStream
Description
Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the user running BuildStream, via symlinks as part of source fetching. The impact of this issue is mitigated by: * BuildStream projects should only use trusted sources in their elements as otherwise the build output can also not be trusted * Tracking a source tarball pins its SHA256 hash, which prevents MITM attacks of users that are fetching an already tracked project * When running on Python >= 3.12, BuildStream >= 2.3.0 already makes use of the Python `tarfile` filter functionality, which blocks the symlink escape Users are recommended to upgrade to version 2.8.1, which fixes this issue.
CVSS v3.1
Score 9.8critical
Affected software
Apache Software Foundation
Apache BuildStream
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache BuildStream versions up to 2.8.0 running on Python versions below 3.12 have an improper link resolution vulnerability (CWE-59) in the tar source plugin. This flaw allows malicious tarballs to exploit symlink following to write files on the host system with the privileges of the BuildStream user during source fetching. Mitigations include using trusted sources, SHA256 hash pinning to prevent MITM attacks, and the use of Python 3.12's tarfile filter functionality in BuildStream 2.3.0 and later, which blocks symlink escapes. The issue is resolved in BuildStream version 2.8.1.
Potential Impact
An attacker controlling a malicious source tarball can write arbitrary files on the host system with the privileges of the user running BuildStream. This could lead to unauthorized file modifications or code execution within the context of the BuildStream user. However, the impact is mitigated if only trusted sources are used, source tarballs are pinned by SHA256 hashes, or if running on Python 3.12 or later with BuildStream 2.3.0 or newer.
Mitigation Recommendations
Users should upgrade to Apache BuildStream version 2.8.1, which fixes this vulnerability. Additionally, ensure that only trusted sources are used for BuildStream elements and that source tarballs are pinned by SHA256 hashes to prevent MITM attacks. Running BuildStream on Python 3.12 or later also mitigates this issue due to improved tarfile handling.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-08-28T14:59:00.996Z
- State
- PUBLISHED
Threat ID: 6ab37d4cf7a7c541066f2eee
Added to database: 09/23/2026, 07:18:36 UTC
Last enriched: 09/23/2026, 07:32:42 UTC
Last updated: 09/24/2026, 01:57:04 UTC
Views: 23
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.