Black Lantern Security BBOT是Black Lantern Security公司开源的一个递归互联网扫描器。 Black Lantern Security BBOT 2.8.4及之前版本存在后置链接漏洞,该漏洞源于github_workflows模块在构造目录路径时未验证符号链接,可能导致本地攻击者植入符号链接,将工作流数据写入攻击者选择的位置。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Black Lantern Security | BBOT | 2.0.0≤ <=2.8.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Black Lantern Security | BBOT | 2.0.0 ~ <=2.8.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12568 | 6.5 MEDIUM | Arbitrary File Write in postman_download module |
| CVE-2026-12565 | 5.3 MEDIUM | Path Traversal (Zip-Slip) in unarchive module |
| CVE-2026-12566 | 3.1 LOW | SSRF via unvalidated WWW-Authenticate realm in docker_pull module |
No comments yet