Moderate severityNVD Advisory· Published Jun 17, 2026
Arbitrary File Write in postman_download module
CVE-2026-12568
Description
The postman_download module uses the workspace name field from the Postman API to construct the local directory path without sanitization. If a malicious workspace has a name containing path traversal characters, pathlib resolves the path outside the intended output directory, allowing an attacker to write arbitrary files to the user's system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
bbotPyPI | >= 2.1.0, < 2.8.6 | 2.8.6 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.