Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
3.1
CVE-2026-14967
- EPSS 0.2%
- Veröffentlicht 08.07.2026 15:03:50
- Zuletzt bearbeitet 19.08.2026 17:27:17
BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the intended folder. T...
3.1
CVE-2026-14966
- EPSS 0.29%
- Veröffentlicht 08.07.2026 15:03:47
- Zuletzt bearbeitet 19.08.2026 17:28:17
BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as produced by legacy versions of p7zip...
1