CRITICAL 9.6 PyPI

BBOT's various issues in unarchive.py can cause arbitrary file write and RCE

GHSA-fhw8-8v9p-7jp7 · CVE-2025-10284 · PYSEC-2026-292

Published · Modified

Description

Summary

Various issues in bbot's unarchive.py allow a malicious site to cause bbot to write arbitrary files to arbitrary locations. This can be used to achieve Remote Code Execution (RCE).

Impact

A user who uses bbot to scan a malicious webserver may have arbitrary code executed on their system.

Ready to move

Start Securing

Free, no credit card | First findings in minutes