Black Lantern Security BBOT是Black Lantern Security公司开源的一个递归互联网扫描器。 Black Lantern Security BBOT 2.1.0版本及之前版本存在路径遍历漏洞,该漏洞源于postman_download模块使用Postman API中的工作区名称字段构建本地目录路径时未进行清理,可能导致具有路径遍历字符的恶意工作区名称使路径解析超出预期输出目录,进而允许攻击者向用户系统写入任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Black Lantern Security | BBOT | 2.1.0≤ <=2.8.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Black Lantern Security | BBOT | 2.1.0 ~ <=2.8.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12565 | 5.3 MEDIUM | Path Traversal (Zip-Slip) in unarchive module |
| CVE-2026-12566 | 3.1 LOW | SSRF via unvalidated WWW-Authenticate realm in docker_pull module |
| CVE-2026-12567 | 2.2 LOW | Symlink-following arbitrary write via github_workflows module |
No comments yet