
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-10282 is a sensitive information exposure vulnerability in BBOT's gitlab.py module that can leak a user's globally configured GitLab API key to an attacker-controlled server via a maliciously formatted git URL. It affects BBOT versions prior to 2.7.0 and versions 2.7.0.6919rc0 through 2.7.2 (exclusive), with the patched version being 2.7.2. The vulnerability was published on October 9, 2025, and carries a CVSS v3.1 base score of 4.7 (Medium) (GitHub Advisory, Red Hat).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). BBOT's gitlab.py module sends the user's globally configured gitlab API key to on-premise GitLab instances without adequately validating the target server's trustworthiness. An attacker can craft a malicious git URL that, when processed by BBOT during a scan, causes the tool to transmit the API key to an attacker-controlled server. Exploitation requires user interaction — specifically, a user must run BBOT against a malicious web server — and no authentication is required on the attacker's side (GitHub Advisory, Black Lantern Security Blog).
Successful exploitation results in the disclosure of the victim's GitLab API key to an unauthorized party, compromising confidentiality. With a leaked GitLab API key, an attacker could gain unauthorized access to GitLab repositories, CI/CD pipelines, secrets, and other resources associated with the compromised account. There is no direct integrity or availability impact from the vulnerability itself, but secondary consequences such as source code theft, supply chain compromise, or further credential abuse are plausible (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.029% (9th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a user to actively run BBOT against an attacker-controlled server, limiting the attack surface to scenarios where social engineering or malicious scan targets are involved (GitHub Advisory).
gitlab.py module during reconnaissance (e.g., embedding the URL in a target's web content or providing it as a scan target).gitlab API key configured) into running a BBOT scan that includes or resolves to the attacker-controlled server.gitlab.py module processes the malicious git URL, it sends the configured GitLab API key in the request to the attacker's server, where it is logged.PRIVATE-TOKEN or Authorization headers with GitLab API key values.gitlab module making requests to domains or IPs not associated with legitimate GitLab infrastructure.Users should upgrade BBOT to version 2.7.2 or later, which patches this vulnerability (GitHub Advisory). As an interim measure, users should avoid running BBOT scans against untrusted or unknown targets when a GitLab API key is configured. Additionally, rotating any potentially exposed GitLab API keys and enabling GitLab audit logging to monitor for unauthorized API usage is strongly recommended (GitHub Advisory).
The vulnerability was reported by researcher justinsteven and published by TheTechromancer (a Black Lantern Security contributor) on October 9, 2025. Black Lantern Security, the maintainer of BBOT, published a dedicated security advisory blog post detailing the issue (Black Lantern Security Blog). No significant broader media coverage or notable community debate has been observed beyond the initial advisory.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."