Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m54h-vhf9-3w3m | BBOT: Arbitrary File Write in postman_download Module |
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Black Lantern Security
Black Lantern Security bbot |
|
| Vendors & Products |
Black Lantern Security
Black Lantern Security bbot |
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The postman_download module uses the workspace name field from the Postman API to construct the local directory path without sanitization. If a malicious workspace has a name containing path traversal characters, pathlib resolves the path outside the intended output directory, allowing an attacker to write arbitrary files to the user's system. | |
| Title | Arbitrary File Write in postman_download module | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: BLSOPS
Published:
Updated: 2026-06-18T12:48:02.115Z
Reserved: 2026-06-17T21:51:43.456Z
Link: CVE-2026-12568
Updated: 2026-06-18T12:47:58.375Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:56:47Z
Github GHSA