3.1

CVE-2026-14966

Symlink guard bypass in unarchive module allows planting symlinks during extraction

BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as produced by legacy versions of p7zip. Such an archive, downloaded and extracted during a scan (for example via filedownload), bypassed the guard and caused an attacker-controlled symlink to be written into the extraction directory. The effect is limited to planting the symlink (its target is not written through), and only hosts using such a legacy p7zip build are affected; current mainline 7-Zip is not.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Blacklanternsecurity ≫ Bbot Version >= 2.3.1 <= 2.8.6
Blacklanternsecurity ≫ Bbot Version 3.0.0.0 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.647 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.649 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.652 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.654 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.659 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.669 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.671 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.673 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.691 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.765 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.767 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.773 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.782 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.786 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.793 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.795 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.798 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.819 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.821 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.829 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.836 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.849 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.851 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.858 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.870 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.876 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.884 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.897 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.903 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.907 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.909 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.981 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.986 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1056 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1062 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1064 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1068 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1070 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1079 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1137 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1139 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1141 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1153 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1173 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1184 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1190 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1254 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1271 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1274 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1304 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1313 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1317 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1333 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1343 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1345 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1349 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1386 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1388 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1390 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1401 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1407 Update rc
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.209
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cves@blacklanternsecurity.com 3.1 1.6 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

https://github.com/blacklanternsecurity/bbot/commit/a3f1a2292e2b0a553827c6175b761abe28807735
Patch