CVE-2026-14967

LOW

Path traversal in github_workflows allows writing artifacts outside output directory

Title source: cna
STIX 2.1

Description

BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the intended folder. The write is bounded to two directory levels above the output location and its target is determined by the operator's configuration, not the attacker.

Scores

CVSS v3 3.1
EPSS 0.0020
EPSS Percentile 9.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
Black Lantern Security/BBOT 1.1.7 - 2.8.6
Published Jul 08, 2026
Tracked Since Jul 08, 2026