OSV 1.4.0 · github-reviewed · 修改于 2026-06-20 05:15
发布时间
2026-06-20 05:15
GitHub 审查时间
2026-06-20 05:15
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/06/GHSA-f9m7-vc86-p6jj/GHSA-f9m7-vc86-p6jj.json
The go.qbee.io/transport library is affected by a symlink-chain path traversal vulnerability in its extractTar routine. The library's path validation is strictly lexical and fails to account for on-disk symlinks created earlier in the extraction process. Consequently, a crafted tar archive can be used to write or overwrite files one directory level above the intended extraction path. In the case of qbee-agent, which runs with root privileges, this vulnerability permits a root-privileged file write outside the intended destination.
The issue has been addressed in version v1.26.25