GHSA-xj69-cqwc-2w67HighCVSS 8.8

Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18...

Published
July 27, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute arbitrary code as the Cribl server process via a crafted Git repository containing a symbolic link in the pack's functions directory.

🔗 References (4)