CVE 9.6 CRITICAL

Improper Archive Extraction in unarchive Enables RCE_CVE-2025-10284

9.6 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Description

BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution.

Basic Information

ID CVE-2025-10284
Source BLSOPS
Published Oct 9, 2025 at 15:46
Modified Oct 9, 2025 at 15:55

Affected Product

Vendor BLSOPS, LLC
Product bbot
Version 0.0.0
Affected Versions BLSOPS, LLC bbot 0.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.