Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3vgw-585j-4m45 | BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284 |
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Black Lantern Security
Black Lantern Security bbot |
|
| Vendors & Products |
Black Lantern Security
Black Lantern Security bbot |
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavior of external tools (e.g. GNU tar) which varies by platform. While CVE-2025-10284 addressed git-specific RCE vectors, the underlying archive extraction path traversal was never fixed. On systems with GNU tar < 1.34 (Ubuntu 20.04, Debian Buster, CentOS 7, many Docker base images), a malicious archive can write files outside the intended extraction directory. | |
| Title | Path Traversal (Zip-Slip) in unarchive module | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: BLSOPS
Published:
Updated: 2026-06-18T12:51:01.213Z
Reserved: 2026-06-17T21:31:34.919Z
Link: CVE-2026-12565
Updated: 2026-06-18T12:50:57.312Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:56:53Z
Github GHSA