Impact
The qbee transport component implements a remote access protocol for the qbee-agent and contains a path traversal flaw in its extractTar routine. Prior to version 1.26.25, the routine uses strictly lexical path validation that does not account for on‑disk symlinks created earlier in the extraction process. An attacker can craft a tar archive that includes a chain of symlinks; during extraction the chain resolves to a location one directory level above the intended destination, allowing the agent to write or overwrite files outside the target directory when the extraction is executed with root privileges. The resulting capability is privileged file creation or modification outside the desired extraction path.
Affected Systems
qbee‑io/transport versions older than 1.26.25 are affected. Systems that deploy the qbee-agent and run the transport component with elevated privileges, such as managed device fleets or edge gateways that receive tar archives over the network, fall within the scope of this vulnerability.
Risk and Exploitability
The CVSS score of 6.0 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a malicious tar file to the agent or to have local access to a process running as root; based on the description it is inferred that the flaw can only be abused if the agent is exposed to untrusted input, and therefore the overall risk remains moderate, with serious consequences only if the attack succeeds.
OpenCVE Enrichment
Github GHSA