Junglewise Threat Intelligence

CVE-2026-14967: Black Lantern Security BBOT path traversal in github_workflows module

CVE-2026-14967 · Severity: low · CVSS 3.1 · Published 2026-07-08

Technologies: Black Lantern Security Bbot. Vendors: PyPI.

Executive brief

BBOT, an OSINT automation framework, contains a flaw in its GitHub Workflows module that could allow files to be saved in unintended locations on the operator's system. By providing a specially crafted repository URL, an attacker could trick the tool into writing downloaded data up to two directory levels outside of the designated output folder. While the attacker cannot choose the specific file name or destination—which are determined by the user's configuration—this could lead to minor data integrity issues or organizational clutter.

Technical details

A path traversal vulnerability (CWE-22) exists in the `github_workflows` module of BBOT due to insufficient validation of the `CODE_REPOSITORY` URL. The path-containment check failed to resolve dot-dot (`..`) sequences before validation, allowing a crafted URL to escape the intended output directory. The exploit is limited to two directory levels above the configured output location, and the final target path is determined by the operator's configuration rather than direct attacker input. This requires the operator to interact with a malicious repository URL. The issue was addressed in a commit that ensures paths are resolved and filenames are sanitized before writing to disk.

Affected products

  • Black Lantern Security BBOT 1.1.7 to 2.8.6

Timeline

  • 2026-07-08: advisory: NVD publication date
  • 2026-07-08: disclosed: Vulnerability details published by Black Lantern Security

References

Related threats