PT-2026-50563 · Black Lantern Security · Bbot
Published
2026-06-17
·
Updated
2026-06-18
·
CVE-2026-12568
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Postman Download Module (affected versions not specified)
Description
The
postman download module fails to sanitize the workspace name field retrieved from the Postman API when constructing local directory paths. A malicious workspace name containing path traversal characters—a technique used to access files and directories outside the intended folder—allows the pathlib library to resolve paths outside the designated output directory, enabling an attacker to write arbitrary files to the user's system.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bbot