Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2394
  • PyPI/bbot
BBOT: Symlink-Following Arbitrary Write via github_workflows Module 13 Jul
  • Fix available
  • Severity - 2.2 (Low)
PYSEC-2026-2393
  • PyPI/bbot
BBOT: Arbitrary File Write in postman_download Module 13 Jul
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-2391
  • PyPI/bbot
BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing 13 Jul
  • Fix available
  • Severity - 3.1 (Low)
PYSEC-2026-2392
  • PyPI/bbot
BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284 13 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1217
  • PyPI/bbot
BBOT's gitlab.py exposes globally configured "gitlab" API key 07 Jul
  • Fix available
  • Severity - 4.7 (Medium)
PYSEC-2026-1216
  • PyPI/bbot
BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver 07 Jul
  • Fix available
  • Severity - 4.7 (Medium)
PYSEC-2026-292
  • PyPI/bbot
BBOT's various issues in unarchive.py can cause arbitrary file write and RCE 29 Jun
  • Fix available
  • Severity - 9.6 (Critical)
PYSEC-2026-293
  • PyPI/bbot
BBOT's insufficient sanitization issues in gitdumper.py can lead to RCE 29 Jun
  • Fix available
  • Severity - 9.6 (Critical)
GHSA-rvp7-w75q-9fv2
  • PyPI/bbot
BBOT: Symlink-Following Arbitrary Write via github_workflows Module 18 Jun
  • Fix available
  • Severity - 2.2 (Low)
GHSA-m54h-vhf9-3w3m
  • PyPI/bbot
BBOT: Arbitrary File Write in postman_download Module 18 Jun
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-3mp7-vp6j-2mxx
  • PyPI/bbot
BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing 18 Jun
  • Fix available
  • Severity - 3.1 (Low)
GHSA-3vgw-585j-4m45
  • PyPI/bbot
BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284 18 Jun
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-p3v4-c93g-cmhw
  • PyPI/bbot
BBOT's gitlab.py exposes globally configured "gitlab" API key 27 Oct 2025
  • Fix available
  • Severity - 4.7 (Medium)
GHSA-h6m2-r6h9-4c44
  • PyPI/bbot
BBOT's insufficient sanitization issues in gitdumper.py can lead to RCE 09 Oct 2025
  • Fix available
  • Severity - 9.6 (Critical)
GHSA-63wh-p5fx-h4vc
  • PyPI/bbot
BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver 09 Oct 2025
  • Fix available
  • Severity - 4.7 (Medium)
GHSA-fhw8-8v9p-7jp7
  • PyPI/bbot
BBOT's various issues in unarchive.py can cause arbitrary file write and RCE 09 Oct 2025
  • Fix available
  • Severity - 9.6 (Critical)