boxlite-cli vulnerabilities
CVEs whose affected-version data names the boxlite-cli package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-46695Critical· 10.0BoxLite: Permission Bypass Allows Modification of Read-Only Files
BoxLite: Permission Bypass Allows Modification of Read-Only Files
▾ Midnightboxlite · boxliteEPSS 0.29%via OSV
CVE-2026-46703Critical· 9.6Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
▾ Midnightboxlite · boxliteEPSS 0.48%via OSV