Filtered by vendor Black Lantern Security
Subscriptions
Total
4 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-12565 | 1 Black Lantern Security | 1 Bbot | 2026-06-21 | 5.3 Medium |
| The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavior of external tools (e.g. GNU tar) which varies by platform. While CVE-2025-10284 addressed git-specific RCE vectors, the underlying archive extraction path traversal was never fixed. On systems with GNU tar < 1.34 (Ubuntu 20.04, Debian Buster, CentOS 7, many Docker base images), a malicious archive can write files outside the intended extraction directory. | ||||
| CVE-2026-12566 | 1 Black Lantern Security | 1 Bbot | 2026-06-21 | 3.1 Low |
| The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in a man-in-the-middle position between bbot and a Docker registry could modify this header to redirect the authentication request to an arbitrary endpoint, potentially leaking authentication tokens. | ||||
| CVE-2026-12567 | 1 Black Lantern Security | 1 Bbot | 2026-06-21 | 2.2 Low |
| The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacker sharing the scan directory can plant a symlink at the predictable output path, causing workflow data to be written to an attacker-chosen location. | ||||
| CVE-2026-12568 | 1 Black Lantern Security | 1 Bbot | 2026-06-21 | 6.5 Medium |
| The postman_download module uses the workspace name field from the Postman API to construct the local directory path without sanitization. If a malicious workspace has a name containing path traversal characters, pathlib resolves the path outside the intended output directory, allowing an attacker to write arbitrary files to the user's system. | ||||
Page 1 of 1.
ReportizFlow