BOSH CLI Tool Path Traversal Vulnerability in Blobs.yml Allows Arbitrary File Writes

Vulnerability

A path traversal vulnerability has been identified in the BOSH CLI tool, specifically in versions prior to 7.10.4. This vulnerability allows an attacker to write arbitrary files and exfiltrate sensitive information by exploiting the 'blobs.yml' path key traversal issue.

Impact

Exploitation of this vulnerability could lead to unauthorized file writes and the exfiltration of sensitive information.

Remediation

Users are advised to upgrade the BOSH CLI tool to version 7.10.4 or greater.

Added: Jul 9, 2026, 7:25 AM
Updated: Jul 9, 2026, 7:25 AM

Vulnerability Rating

Custom Algorithm
spread
1.2
impact
3.1
exploitability
4.2
remediation
7.7
relevance
9.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.