Περιγραφή
BBOT-s `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the intended folder. The write is bounded to two directory levels above the output location and its target is determined by the operator-s configuration, not the attacker.
CVSS 3.1EPSS 0.198%Κίνδυνος 0.32
Προβολή πηγής- Δημοσίευση
- 2026-07-08 16:16:27
- Επηρεαζόμενες εκδόσεις
- unknown
- Τύπος
- Κρίσιμο λογισμικό
- Διάνυσμα
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N