BBOT's various issues in unarchive.py can cause arbitrary file write and RCE
Critical severity
GitHub Reviewed
Published
Oct 9, 2025
in
blacklanternsecurity/bbot
•
Updated Oct 9, 2025
Description
Published by the National Vulnerability Database
Oct 9, 2025
Published to the GitHub Advisory Database
Oct 9, 2025
Reviewed
Oct 9, 2025
Last updated
Oct 9, 2025
Summary
Various issues in bbot's
unarchive.py
allow a malicious site to cause bbot to write arbitrary files to arbitrary locations. This can be used to achieve Remote Code Execution (RCE).Impact
A user who uses bbot to scan a malicious webserver may have arbitrary code executed on their system.
References