Exposure of API Key in BBOT's GitLab Module
CVE-2025-10282

4.7MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 October 2025

What is CVE-2025-10282?

The BBOT GitLab module has a security weakness that can be exploited by attackers to disclose sensitive GitLab API keys. This vulnerability arises from the processing of maliciously formatted git URLs, which, when sent to the server, can lead to unauthorized access of the API keys stored on the server. Proper security measures are essential to mitigate this risk and protect user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

bbot Linux 0.0.0 <= 2.6.1

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.