Executive brief
A vulnerability exists in the BBOT security tool's Postman download module, which is used to fetch data from Postman API workspaces. If a user interacts with a malicious Postman workspace, the tool can be tricked into writing files to unintended locations on the user's computer. This could allow an attacker to overwrite sensitive system files or configuration data, potentially compromising the integrity of the user's system.
Technical details
A path traversal vulnerability (CWE-22) exists in the postman_download.py module of BBOT versions 2.1.0 through 2.8.5. The module uses the 'name' field from the Postman API to construct local directory paths using pathlib without proper sanitization. An attacker can create a malicious Postman workspace with a name containing traversal sequences (e.g., '../'). When a BBOT user attempts to download this workspace, the application resolves the path outside of the intended output directory, enabling arbitrary file writes on the host system. The issue was addressed in commit 36bc208 by implementing 'tagify' on the workspace name and verifying that the resolved path remains relative to the intended output directory.
Affected products
- Black Lantern Security BBOT 2.1.0 to 2.8.5
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory
- 2026-06-17: patched: Fixed in commit 36bc20818