Security: blacklanternsecurity/bbot
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284GHSA-3vgw-585j-4m45 published
Jun 17, 2026 by liquidsecModerate -
Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsingGHSA-3mp7-vp6j-2mxx published
Jun 17, 2026 by liquidsecLow -
Symlink-Following Arbitrary Write via github_workflows Module in BBOTGHSA-rvp7-w75q-9fv2 published
Jun 17, 2026 by liquidsecLow -
Arbitrary File Write in postman_download ModuleGHSA-m54h-vhf9-3w3m published
Jun 17, 2026 by liquidsecModerate -
git_clone.py can be made to expose a user's github.com API key to an attacker-controlled webserverGHSA-63wh-p5fx-h4vc published
Oct 9, 2025 by TheTechromancerModerate -
gitlab.py exposes globally configured "gitlab" API key to on-premise GitLab instances, potentially threatening confidentiality of a gitlab.com API keyGHSA-p3v4-c93g-cmhw published
Oct 9, 2025 by TheTechromancerModerate -
Various issues in gitdumper.py can cause RCEGHSA-h6m2-r6h9-4c44 published
Oct 9, 2025 by TheTechromancerCritical -
Various issues in unarchive.py can cause arbitrary file write and RCEGHSA-fhw8-8v9p-7jp7 published
Oct 9, 2025 by TheTechromancerCritical
Learn more about advisories related to blacklanternsecurity/bbot in the GitHub Advisory Database