Path Traversal Vulnerability in Postman API by Black Lantern Security
CVE-2026-12568
6.5MEDIUM
What is CVE-2026-12568?
The postman_download module in the Postman API is susceptible to a path traversal vulnerability due to unsafe handling of the workspace name field. When a workspace is named with certain malicious characters, it can lead to the construction of an unintended file path, potentially allowing an attacker to write arbitrary files anywhere in the user's system. This occurs as the system does not perform necessary sanitization of the input, which can have serious implications for system integrity and security.
Affected Version(s)
BBOT 2.1.0
