BBOT's gitlab.py exposes globally configured "gitlab" API key
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Oct 9, 2025 
          in
          
            blacklanternsecurity/bbot
          
          •
          Updated Oct 27, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Oct 9, 2025 
    
  
        Published to the GitHub Advisory Database
      Oct 27, 2025 
    
  
        Reviewed
      Oct 27, 2025 
    
  
        Last updated
      Oct 27, 2025 
    
  
Summary
bbot's
gitlab.pysends the user's "gitlab" API key to on-premise GitLab instances.If a user has configured a gitlab.com API key using this mechanism, it may be leaked to an attacker-controlled server.
Impact
A user with a "gitlab" API key configured who uses bbot to scan a malicious webserver may leak their gitlab.com API key to an untrustworthy server.
References