← Voltar à pesquisa de CVEs

CVE-2026-14967

BBOT-s

Descrição

BBOT-s `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the intended folder. The write is bounded to two directory levels above the output location and its target is determined by the operator-s configuration, not the attacker.

CVSS 3.1EPSS 0.198%Risco 0.32
Ver fonte
Publicação
2026-07-08 16:16:27
Versões afetadas
unknown
Tipo
Software crítico
Vetor
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N