BBOT's insufficient sanitization issues in gitdumper.py can lead to RCE
Critical severity
GitHub Reviewed
Published
Oct 9, 2025
in
blacklanternsecurity/bbot
•
Updated Oct 9, 2025
Description
Published by the National Vulnerability Database
Oct 9, 2025
Published to the GitHub Advisory Database
Oct 9, 2025
Reviewed
Oct 9, 2025
Last updated
Oct 9, 2025
Summary
bbot's
gitdumper.py
insufficiently sanitises a.git/config
file, leading to Remote Code Execution (RCE).bbot's
gitdumper.py
can be made to consume a malicious.git/index
file, leading to arbitrary file write which can be used to achieve Remote Code Execution (RCE).Impact
A user who uses bbot to scan a malicious webserver may have arbitrary code executed on their system.
References