« Volver al listado

Blacklanternsecurity

Blacklanternsecurity Bbot: vulnerabilidades y CVE

Blacklanternsecurity Bbot tiene 7 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses7
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-14967Baja (3.1)0.26%—8 jul 2026
BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could…
CVE-2026-14966Baja (3.1)0.38%—8 jul 2026
BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as…
CVE-2026-12566Baja (3.1)0.17%—17 jun 2026
The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in a man-in-the-middle position between bbot and a…
CVE-2025-10284Crítica (9.6)0.71%—9 oct 2025
BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution.
CVE-2025-10283Crítica (9.6)0.48%—9 oct 2025
BBOT's gitdumper module could be abused to execute commands through a malicious git repository.
CVE-2025-10282Media (4.7)0.23%—9 oct 2025
BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious formatted git URL.
CVE-2025-10281Media (4.7)0.23%—9 oct 2025
BBOT's git_clone module could be abused to disclose a GitHub API key to an attacker controlled server with a malicious formatted git URL.