CRITICAL 9.6 PyPI

BBOT's insufficient sanitization issues in gitdumper.py can lead to RCE

GHSA-h6m2-r6h9-4c44 · CVE-2025-10283 · PYSEC-2026-293

Published · Modified

Description

Summary

bbot's gitdumper.py insufficiently sanitises a .git/config file, leading to Remote Code Execution (RCE).

bbot's gitdumper.py can be made to consume a malicious .git/index file, leading to arbitrary file write which can be used to achieve Remote Code Execution (RCE).

Impact

A user who uses bbot to scan a malicious webserver may have arbitrary code executed on their system.

Ready to move

Start Securing

Free, no credit card | First findings in minutes