BBOT's gitlab.py exposes globally configured "gitlab" API key
Moderate severity
GitHub Reviewed
Published
Oct 9, 2025
in
blacklanternsecurity/bbot
•
Updated Oct 27, 2025
Description
Published by the National Vulnerability Database
Oct 9, 2025
Published to the GitHub Advisory Database
Oct 27, 2025
Reviewed
Oct 27, 2025
Last updated
Oct 27, 2025
Summary
bbot's
gitlab.pysends the user's "gitlab" API key to on-premise GitLab instances.If a user has configured a gitlab.com API key using this mechanism, it may be leaked to an attacker-controlled server.
Impact
A user with a "gitlab" API key configured who uses bbot to scan a malicious webserver may leak their gitlab.com API key to an untrustworthy server.
References