CRITICAL9.6CVE-2025-10283BBOT's insufficient sanitization issues in gitdumper.py can lead to RCE from 0, < 2.7.0
CRITICAL9.6CVE-2025-10284BBOT's various issues in unarchive.py can cause arbitrary file write and RCE from 0, < 2.7.0
MEDIUM6.5CVE-2026-12568BBOT: Arbitrary File Write in postman_download Module >= 2.1.0, < 2.8.6
MEDIUM6.5BBOT: Arbitrary File Write in postman_download Module
>= 2.1.0, < 2.8.6
MEDIUM5.3BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
>= 2.3.1, < 2.8.5
MEDIUM5.3BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
>= 2.3.1, < 2.8.5
MEDIUM4.7BBOT's gitlab.py exposes globally configured "gitlab" API key
from 0, < 2.7.2
MEDIUM4.7BBOT's gitlab.py exposes globally configured "gitlab" API key
from 0, < 2.7.2
MEDIUM4.7BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver
from 0, < 2.7.0
MEDIUM4.7BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver
from 0, < 2.7.0
LOW3.1BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
>= 2.0.0, < 2.8.5
LOW3.1BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
>= 2.0.0, < 2.8.5
LOW2.2BBOT: Symlink-Following Arbitrary Write via github_workflows Module
>= 2.0.0, < 2.8.5
LOW2.2BBOT: Symlink-Following Arbitrary Write via github_workflows Module
>= 2.0.0, < 2.8.5