Blacklanternsecurity
Blacklanternsecurity Bbot: vulnerabilidades y CVE
Blacklanternsecurity Bbot tiene 7 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses7
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-14967 | Baja (3.1) | 0.26% | — | 8 jul 2026 | BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could… |
| CVE-2026-14966 | Baja (3.1) | 0.38% | — | 8 jul 2026 | BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as… |
| CVE-2026-12566 | Baja (3.1) | 0.17% | — | 17 jun 2026 | The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in a man-in-the-middle position between bbot and a… |
| CVE-2025-10284 | Crítica (9.6) | 0.71% | — | 9 oct 2025 | BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution. |
| CVE-2025-10283 | Crítica (9.6) | 0.48% | — | 9 oct 2025 | BBOT's gitdumper module could be abused to execute commands through a malicious git repository. |
| CVE-2025-10282 | Media (4.7) | 0.23% | — | 9 oct 2025 | BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious formatted git URL. |
| CVE-2025-10281 | Media (4.7) | 0.23% | — | 9 oct 2025 | BBOT's git_clone module could be abused to disclose a GitHub API key to an attacker controlled server with a malicious formatted git URL. |