MEDIUM 4.7 PyPI

BBOT's gitlab.py exposes globally configured "gitlab" API key

GHSA-p3v4-c93g-cmhw · CVE-2025-10282

Published · Modified

Description

Summary

bbot's gitlab.py sends the user's "gitlab" API key to on-premise GitLab instances.

If a user has configured a gitlab.com API key using this mechanism, it may be leaked to an attacker-controlled server.

Impact

A user with a "gitlab" API key configured who uses bbot to scan a malicious webserver may leak their gitlab.com API key to an untrustworthy server.

Ready to move

Start Securing

Free, no credit card | First findings in minutes