3.1
CVE-2026-14967
- EPSS 0.2%
- Veröffentlicht 08.07.2026 15:03:50
- Zuletzt bearbeitet 19.08.2026 17:27:17
- Erkennungen
Path traversal in github_workflows allows writing artifacts outside output directory
BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the intended folder. The write is bounded to two directory levels above the output location and its target is determined by the operator's configuration, not the attacker.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Blacklanternsecurity ≫ Bbot Version >= 1.1.7 <= 2.8.6
Blacklanternsecurity ≫ Bbot Version 3.0.0.0 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.647 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.649 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.652 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.654 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.659 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.669 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.671 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.673 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.691 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.765 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.767 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.773 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.782 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.786 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.793 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.795 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.798 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.819 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.821 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.829 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.836 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.849 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.851 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.858 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.870 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.876 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.884 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.897 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.903 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.907 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.909 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.981 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.986 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1056 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1062 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1064 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1068 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1070 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1079 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1137 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1139 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1141 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1153 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1173 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1184 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1190 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1254 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1271 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1274 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1304 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1313 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1317 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1333 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1343 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1345 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1349 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1386 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1388 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1390 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1401 Update rc
Blacklanternsecurity ≫ Bbot Version 3.0.0.1407 Update rc
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.098 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cves@blacklanternsecurity.com | 3.1 | 1.6 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
https://github.com/blacklanternsecurity/bbot/commit/c1c6ec05ff998e2fba55a14d1026f12563ccd82f