PT-2025-41396 · Bbot · Bbot

Justin Steven

·

Published

2025-10-09

·

Updated

2025-10-10

·

CVE-2025-10283

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BBOT (affected versions not specified)
Description The gitdumper module in BBOT is susceptible to exploitation, allowing attackers to execute arbitrary commands on the host system. This occurs through the processing of malicious Git repositories. The module, designed to extract data from Git repositories, does not properly sanitize the .git directory, leading to a path traversal condition and potential remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-10283
GHSA-H6M2-R6H9-4C44

Affected Products

Bbot