Symlink Attack Affecting buildstream package, versions [,2.8.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.42% (34th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-BUILDSTREAM-20260800
  • published29 Sept 2026
  • disclosed23 Sept 2026
  • creditUnknown

Introduced: 23 Sep 2026

NewCVE-2026-82331  (opens in a new tab)
CWE-59  (opens in a new tab)

How to fix?

Upgrade BuildStream to version 2.8.1 or higher.

Overview

BuildStream is an A framework for modelling build pipelines in YAML

Affected versions of this package are vulnerable to Symlink Attack in the tar source plugin when handling archive extraction. An attacker can modify or overwrite arbitrary files on the host system by supplying a malicious tarball containing symlinks during the source fetching process. This is only exploitable if the environment is running on Python versions earlier than 3.12 and the user explicitly fetches an untrusted archive.

CVSS Base Scores

version 4.0
version 3.1