PT-2025-41397 · Bbot · Bbot

Justin Steven

·

Published

2025-10-09

·

Updated

2025-10-10

·

CVE-2025-10284

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BBOT (affected versions not specified)
Description The unarchive module in BBOT is susceptible to exploitation through the use of malicious archive files. When these files are extracted, they can trigger arbitrary file writes, potentially leading to remote code execution. An attacker can control write operations by supplying crafted archive payloads. This allows for the execution of arbitrary commands or malicious payloads on the affected system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-10284
GHSA-FHW8-8V9P-7JP7

Affected Products

Bbot