PT-2026-56471 · Bbot · Bbot

·

CVE-2026-14966

·

Published

2026-07-08

·

Updated

2026-07-08

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions BBOT (affected versions not specified)
Description The unarchive module fails to detect symlinks in zip and 7z archives when the listing includes a DOS-attribute prefix before the unix mode, a characteristic of legacy p7zip versions. This allows an attacker to bypass security guards during a scan, such as through the filedownload process, resulting in an attacker-controlled symlink being written into the extraction directory. The impact is limited to the creation of the symlink, as the target is not written through.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14966
PYSEC-2026-3719

Affected Products

Bbot