bbot has 8 CVEs on record between 2025 and 2026. Disclosures have slowed: 2 in the last 90 days after 4 in the 90 before. The busiest recent month was June 2026 with 4. The median CVSS is 3.9 (low). None have a confirmed exploitation report. The most common weakness class is CWE-22 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 3.9
- Publish → KEV
- —
- Last 90 days
- 2 prev 4
Worst active — by depth score
CVE-2026-12568Medium· 6.5BBOT: Arbitrary File Write in postman_download Module36CVE-2026-12565Medium· 5.3BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-1028429CVE-2025-10282Medium· 4.7BBOT's gitlab.py exposes globally configured "gitlab" API key26CVE-2025-10281Medium· 4.7BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver26CVE-2026-14967Low· 3.1BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-contai…17
bbot vulnerabilities
CVEs affecting bbot, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-14967Low· 3.1BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-contai…
BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the inten…
CVE-2026-14966Low· 3.1BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect sy…
BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as produced by legacy vers…
CVE-2026-12566Low· 3.1BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
CVE-2026-12565Medium· 5.3BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
CVE-2026-12568Medium· 6.5BBOT: Arbitrary File Write in postman_download Module
BBOT: Arbitrary File Write in postman_download Module
CVE-2026-12567Low· 2.2BBOT: Symlink-Following Arbitrary Write via github_workflows Module
BBOT: Symlink-Following Arbitrary Write via github_workflows Module
CVE-2025-10282Medium· 4.7BBOT's gitlab.py exposes globally configured "gitlab" API key
BBOT's gitlab.py exposes globally configured "gitlab" API key
CVE-2025-10281Medium· 4.7BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver
BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver