CVE-2026-12568

MEDIUM

Black Lantern Security BBOT - Arbitrary File Write in postman_download Module

Title source: rule
STIX 2.1

Description

The postman_download module uses the workspace name field from the Postman API to construct the local directory path without sanitization. If a malicious workspace has a name containing path traversal characters, pathlib resolves the path outside the intended output directory, allowing an attacker to write arbitrary files to the user's system.

Scores

CVSS v3 6.5
EPSS 0.0025
EPSS Percentile 16.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
Black Lantern Security/BBOT 2.1.0 - <=2.8.5
pypi/bbot 2.1.0 - 2.8.6PyPI
Published Jun 17, 2026
Tracked Since Jun 18, 2026