CVE-2026-55828MEDIUMCVSS 0.0

go.qbee.io/transport: Symlink-chain path traversal in tar extraction (one level outside destination)

Published Jun 19, 2026·Updated Jun 19, 2026

Description

### Impact The go.qbee.io/transport library is affected by a symlink-chain path traversal vulnerability in its extractTar routine. The library's path validation is strictly lexical and fails to account for on-disk symlinks created earlier in the extraction process. Consequently, a crafted tar archive can be used to write or overwrite files one directory level above the intended extraction path. In the case of qbee-agent, which runs with root privileges, this vulnerability permits a root-privileged file write outside the intended destination. ### Patches The issue has been addressed in version v1.26.25

Affected Packages (1)

go.qbee.io/transportGO
Fixed in 1.26.25

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free