Symlink guard bypass in unarchive module allows planting symlinks during extraction
Summary
| CVE | CVE-2026-14966 |
|---|---|
| State | PUBLISHED |
| Assigner | BLSOPS |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-08 16:16:27 UTC |
| Updated | 2026-08-19 17:28:17 UTC |
| Description | BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as produced by legacy versions of p7zip. Such an archive, downloaded and extracted during a scan (for example via filedownload), bypassed the guard and caused an attacker-controlled symlink to be written into the extraction directory. The effect is limited to planting the symlink (its target is not written through), and only hosts using such a legacy p7zip build are affected; current mainline 7-Zip is not. |
Risk And Classification
Primary CVSS: v3.1 3.1 LOW from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS: 0.002910000 probability, percentile 0.217100000 (date 2026-08-19)
Problem Types: CWE-59 | CWE-59 CWE-59 Improper Link Resolution Before File Access ('Link Following')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 3.1 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N |
| 3.1 | CNA | CVSS | 3.1 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Blacklanternsecurity | Bbot | 3.0.0.0 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1056 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1062 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1064 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1068 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1070 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1079 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1137 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1139 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1141 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1153 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1173 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1184 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1190 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1254 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1271 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1274 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1304 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1313 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1317 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1333 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1343 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1345 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1349 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1386 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1388 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1390 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1401 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.1407 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.647 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.649 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.652 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.654 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.659 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.669 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.671 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.673 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.691 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.765 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.767 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.773 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.782 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.786 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.793 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.795 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.798 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.819 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.821 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.829 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.836 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.849 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.851 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.858 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.870 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.876 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.884 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.897 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.903 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.907 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.909 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.981 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | 3.0.0.986 | rc | All | All |
| Application | Blacklanternsecurity | Bbot | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Black Lantern Security | BBOT | affected 2.3.1 2.8.6 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/blacklanternsecurity/bbot/commit/a3f1a2292e2b0a553827c6175b76... | [email protected] | github.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.