bbot vulnerabilities
CVEs whose affected-version data names the bbot package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
8 CVEsRSS
CVE-2026-14967Low· 3.1BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-contai…
BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the inten…
CVE-2026-14966Low· 3.1BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect sy…
BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as produced by legacy vers…
CVE-2026-12566Low· 3.1BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
CVE-2026-12565Medium· 5.3BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
CVE-2026-12568Medium· 6.5BBOT: Arbitrary File Write in postman_download Module
BBOT: Arbitrary File Write in postman_download Module
CVE-2026-12567Low· 2.2BBOT: Symlink-Following Arbitrary Write via github_workflows Module
BBOT: Symlink-Following Arbitrary Write via github_workflows Module
CVE-2025-10282Medium· 4.7BBOT's gitlab.py exposes globally configured "gitlab" API key
BBOT's gitlab.py exposes globally configured "gitlab" API key
CVE-2025-10281Medium· 4.7BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver
BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver