Description
qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-disk symlinks created earlier in the extraction process. A crafted tar archive can use a symlink chain to write or overwrite files one directory level above the intended extraction path. When qbee-agent performs the extraction with root privileges, this permits a root-privileged file write outside the intended destination. This issue is fixed in version 1.26.25.
Published: 2026-09-15
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Root Privileged File Write
Action: Immediate Patch
AI Analysis

Impact

The qbee transport component implements a remote access protocol for the qbee-agent and contains a path traversal flaw in its extractTar routine. Prior to version 1.26.25, the routine uses strictly lexical path validation that does not account for on‑disk symlinks created earlier in the extraction process. An attacker can craft a tar archive that includes a chain of symlinks; during extraction the chain resolves to a location one directory level above the intended destination, allowing the agent to write or overwrite files outside the target directory when the extraction is executed with root privileges. The resulting capability is privileged file creation or modification outside the desired extraction path.

Affected Systems

qbee‑io/transport versions older than 1.26.25 are affected. Systems that deploy the qbee-agent and run the transport component with elevated privileges, such as managed device fleets or edge gateways that receive tar archives over the network, fall within the scope of this vulnerability.

Risk and Exploitability

The CVSS score of 6.0 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a malicious tar file to the agent or to have local access to a process running as root; based on the description it is inferred that the flaw can only be abused if the agent is exposed to untrusted input, and therefore the overall risk remains moderate, with serious consequences only if the attack succeeds.

Generated by OpenCVE AI on September 20, 2026 at 16:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade qbee‑io/transport to version 1.26.25 or later to eliminate the symlink validation bug.
  • Restrict tar extraction to trusted sources only, ensuring that only known safe archives are processed.
  • Configure the filesystem so that only the intended extraction directory is writable by the agent, and monitor for unauthorized writes outside that directory.

Generated by OpenCVE AI on September 20, 2026 at 16:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f9m7-vc86-p6jj go.qbee.io/transport: Symlink-chain path traversal in tar extraction (one level outside destination)
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Qbee-io
Qbee-io transport
Vendors & Products Qbee-io
Qbee-io transport

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-disk symlinks created earlier in the extraction process. A crafted tar archive can use a symlink chain to write or overwrite files one directory level above the intended extraction path. When qbee-agent performs the extraction with root privileges, this permits a root-privileged file write outside the intended destination. This issue is fixed in version 1.26.25.
Title qbee transport: Symlink-chain path traversal in tar extraction (one level outside destination)
Weaknesses CWE-22
CWE-59
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Qbee-io Transport
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T18:02:39.851Z

Reserved: 2026-06-17T16:29:38.864Z

Link: CVE-2026-55828

cve-icon Vulnrichment

Updated: 2026-09-15T17:38:20.534Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:16.367

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-55828

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')