CVE Explorer
CVE-2026-14967
BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the intended folder. The write is bounded to two directory levels above the output location and its target is determined by the operator's configuration, not the attacker.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"BBOT","repo":"https://github.com/blacklanternsecurity/bbot","vendor":"Black Lantern Security","versions":[{"lessThanOrEqual":"2.8.6","status":"affected","version":"1.1.7","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b09f0f94202f9d728d4a8e9ed094d61f9d7c0ea7d43de0aafb9810bc105b8c23 · sha256:77a4c52074ebcb6e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.1,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b09f0f94202f9d728d4a8e9ed094d61f9d7c0ea7d43de0aafb9810bc105b8c23 · sha256:77a4c52074ebcb6e… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b09f0f94202f9d728d4a8e9ed094d61f9d7c0ea7d43de0aafb9810bc105b8c23 · sha256:77a4c52074ebcb6e… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://github.com/blacklanternsecurity/bbot/commit/c1c6ec05ff998e2fba55a14d1026f12563ccd82f"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b09f0f94202f9d728d4a8e9ed094d61f9d7c0ea7d43de0aafb9810bc105b8c23 · sha256:77a4c52074ebcb6e… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.