CVE-2026-55828
qbee transport: Symlink-chain path traversal in tar extraction (one level outside destination)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-disk symlinks created earlier in the extraction process. A crafted tar archive can use a symlink chain to write or overwrite files one directory level above the intended extraction path. When qbee-agent performs the extraction with root privileges, this permits a root-privileged file write outside the intended destination. This issue is fixed in version 1.26.25.
| CWE | CWE-22 CWE-59 |
| Vendor | qbee-io |
| Product | transport |
| Published | Sep 15, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for qbee-io transport
Be the first to know when new unknown vulnerabilities affecting qbee-io transport are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
qbee-io / transport
< 1.26.25