{"id":"CVE-2025-10282","aliases":["GHSA-p3v4-c93g-cmhw","PYSEC-2026-1217"],"title":"BBOT's gitlab.py exposes globally configured \"gitlab\" API key","summary":"BBOT's gitlab.py exposes globally configured \"gitlab\" API key","severity":"medium","cvss":4.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","vendor":"bbot","product":"bbot","ecosystem":"pip","affected":["bbot < 2.7.2","bbot >= 2.7.0.6919rc0, < 2.7.2"],"patched":["bbot 2.7.2","bbot 2.7.2"],"published":"2025-10-27","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-p3v4-c93g-cmhw","references":[{"url":"https://github.com/blacklanternsecurity/bbot/security/advisories/GHSA-p3v4-c93g-cmhw"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-10282"},{"url":"https://blog.blacklanternsecurity.com/p/bbot-security-advisory-gitdumper"},{"url":"https://github.com/blacklanternsecurity/bbot"}],"tags":["osv","pip"],"epss":0.0023,"epssPercentile":0.14071,"ingestedAt":"2026-07-08T18:25:51.505Z","slug":"CVE-2025-10282","body":"## Overview\n\n### Summary\n\nbbot's `gitlab.py` sends the user's \"gitlab\" API key to on-premise GitLab instances.\n\nIf a user has configured a gitlab.com API key using this mechanism, it may be leaked to an attacker-controlled server.\n\n### Impact\n\nA user with a \"gitlab\" API key configured who uses bbot to scan a malicious webserver may leak their gitlab.com API key to an untrustworthy server.\n\n## Affected packages\n\n- `bbot < 2.7.2`\n- `bbot >= 2.7.0.6919rc0, < 2.7.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `bbot 2.7.2`\n- `bbot 2.7.2`","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":25.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}