CVE-2026-14966
EUVD-2026-4229508.07.2026, 16:16
BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as produced by legacy versions of p7zip. Such an archive, downloaded and extracted during a scan (for example via filedownload), bypassed the guard and caused an attacker-controlled symlink to be written into the extraction directory. The effect is limited to planting the symlink (its target is not written through), and only hosts using such a legacy p7zip build are affected; current mainline 7-Zip is not.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| blacklanternsecurity | bbot | 2.3.1 ≤ 𝑥 ≤ 2.8.6 |
| blacklanternsecurity | bbot | 3.0.0.0:rc |
| blacklanternsecurity | bbot | 3.0.0.647:rc |
| blacklanternsecurity | bbot | 3.0.0.649:rc |
| blacklanternsecurity | bbot | 3.0.0.652:rc |
| blacklanternsecurity | bbot | 3.0.0.654:rc |
| blacklanternsecurity | bbot | 3.0.0.659:rc |
| blacklanternsecurity | bbot | 3.0.0.669:rc |
| blacklanternsecurity | bbot | 3.0.0.671:rc |
| blacklanternsecurity | bbot | 3.0.0.673:rc |
| blacklanternsecurity | bbot | 3.0.0.691:rc |
| blacklanternsecurity | bbot | 3.0.0.765:rc |
| blacklanternsecurity | bbot | 3.0.0.767:rc |
| blacklanternsecurity | bbot | 3.0.0.773:rc |
| blacklanternsecurity | bbot | 3.0.0.782:rc |
| blacklanternsecurity | bbot | 3.0.0.786:rc |
| blacklanternsecurity | bbot | 3.0.0.793:rc |
| blacklanternsecurity | bbot | 3.0.0.795:rc |
| blacklanternsecurity | bbot | 3.0.0.798:rc |
| blacklanternsecurity | bbot | 3.0.0.819:rc |
| blacklanternsecurity | bbot | 3.0.0.821:rc |
| blacklanternsecurity | bbot | 3.0.0.829:rc |
| blacklanternsecurity | bbot | 3.0.0.836:rc |
| blacklanternsecurity | bbot | 3.0.0.849:rc |
| blacklanternsecurity | bbot | 3.0.0.851:rc |
| blacklanternsecurity | bbot | 3.0.0.858:rc |
| blacklanternsecurity | bbot | 3.0.0.870:rc |
| blacklanternsecurity | bbot | 3.0.0.876:rc |
| blacklanternsecurity | bbot | 3.0.0.884:rc |
| blacklanternsecurity | bbot | 3.0.0.897:rc |
| blacklanternsecurity | bbot | 3.0.0.903:rc |
| blacklanternsecurity | bbot | 3.0.0.907:rc |
| blacklanternsecurity | bbot | 3.0.0.909:rc |
| blacklanternsecurity | bbot | 3.0.0.981:rc |
| blacklanternsecurity | bbot | 3.0.0.986:rc |
| blacklanternsecurity | bbot | 3.0.0.1056:rc |
| blacklanternsecurity | bbot | 3.0.0.1062:rc |
| blacklanternsecurity | bbot | 3.0.0.1064:rc |
| blacklanternsecurity | bbot | 3.0.0.1068:rc |
| blacklanternsecurity | bbot | 3.0.0.1070:rc |
| blacklanternsecurity | bbot | 3.0.0.1079:rc |
| blacklanternsecurity | bbot | 3.0.0.1137:rc |
| blacklanternsecurity | bbot | 3.0.0.1139:rc |
| blacklanternsecurity | bbot | 3.0.0.1141:rc |
| blacklanternsecurity | bbot | 3.0.0.1153:rc |
| blacklanternsecurity | bbot | 3.0.0.1173:rc |
| blacklanternsecurity | bbot | 3.0.0.1184:rc |
| blacklanternsecurity | bbot | 3.0.0.1190:rc |
| blacklanternsecurity | bbot | 3.0.0.1254:rc |
| blacklanternsecurity | bbot | 3.0.0.1271:rc |
| blacklanternsecurity | bbot | 3.0.0.1274:rc |
| blacklanternsecurity | bbot | 3.0.0.1304:rc |
| blacklanternsecurity | bbot | 3.0.0.1313:rc |
| blacklanternsecurity | bbot | 3.0.0.1317:rc |
| blacklanternsecurity | bbot | 3.0.0.1333:rc |
| blacklanternsecurity | bbot | 3.0.0.1343:rc |
| blacklanternsecurity | bbot | 3.0.0.1345:rc |
| blacklanternsecurity | bbot | 3.0.0.1349:rc |
| blacklanternsecurity | bbot | 3.0.0.1386:rc |
| blacklanternsecurity | bbot | 3.0.0.1388:rc |
| blacklanternsecurity | bbot | 3.0.0.1390:rc |
| blacklanternsecurity | bbot | 3.0.0.1401:rc |
| blacklanternsecurity | bbot | 3.0.0.1407:rc |
𝑥
= Vulnerable software versions