VulnSea

bbot has 8 CVEs on record between 2025 and 2026. Disclosures have slowed: 2 in the last 90 days after 4 in the 90 before. The busiest recent month was June 2026 with 4. The median CVSS is 3.9 (low). None have a confirmed exploitation report. The most common weakness class is CWE-22 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
3.9
Publish → KEV
Last 90 days
2 prev 4

Products

  • bbot 8
8
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

bbot vulnerabilities

CVEs affecting bbot, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-14967Low· 3.1
2mo ago

BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-contai…

BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the inten…

Sunlitbbot · bbotEPSS 0.26%via OSV
CVE-2026-14966Low· 3.1
2mo ago

BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect sy…

BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as produced by legacy vers…

Sunlitbbot · bbotEPSS 0.38%via OSV
CVE-2026-12566Low· 3.1
3mo ago

BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing

BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing

Sunlitbbot · bbotEPSS 0.17%via GHSA
CVE-2026-12565Medium· 5.3
3mo ago

BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284

BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284

Sunlitbbot · bbotEPSS 0.21%via GHSA
CVE-2026-12568Medium· 6.5
3mo ago

BBOT: Arbitrary File Write in postman_download Module

BBOT: Arbitrary File Write in postman_download Module

Sunlitbbot · bbotEPSS 0.25%via GHSA
CVE-2026-12567Low· 2.2
3mo ago

BBOT: Symlink-Following Arbitrary Write via github_workflows Module

BBOT: Symlink-Following Arbitrary Write via github_workflows Module

Sunlitbbot · bbotEPSS 0.09%via GHSA
CVE-2025-10282Medium· 4.7
11mo ago

BBOT's gitlab.py exposes globally configured "gitlab" API key

BBOT's gitlab.py exposes globally configured "gitlab" API key

Sunlitbbot · bbotEPSS 0.23%via OSV
CVE-2025-10281Medium· 4.7
11mo ago

BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver

BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver

Sunlitbbot · bbotEPSS 0.23%via OSV
bbot vulnerabilities (CVEs) · VulnSea