SecBoard
Zurück zur CVE-Übersicht

CVE-2026-12567

LOW(2.2)

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N

Risk Signal Score11/100 — NIEDRIG

EPSS-Score

0%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

2.2

Technische Schwere

Beschreibung

The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacker sharing the scan directory can plant a symlink at the predictable output path, causing workflow data to be written to an attacker-chosen location.

GitHub Advisories

GHSA-rvp7-w75q-9fv2LOW

BBOT: Symlink-Following Arbitrary Write via github_workflows Module

pip/bbot2.8.5
GitHub Advisory

Referenzen