Description
The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information.
Affected versions: BOSH CLI tool versions prior to v7.10.4.
Published: 2026-07-09
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The blobs.yml path key in the BOSH CLI tool can be crafted so that the CLI writes files outside its intended directory, allowing arbitrary file creation and the potential exfiltration of sensitive data. This flaw is a path traversal weakness (CWE-22) that also exposes information (CWE-200).

Affected Systems

CloudFoundry Foundation BOSH Command Line Interface versions earlier than v7.10.4 are vulnerable; any installation that processes user‑supplied blobs.yml files without the patch is at risk.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity, while the EPSS score of less than 1% shows current exploitation probability is low and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker would need to provide or modify a blobs.yml file that the CLI processes, for example via a malicious buildpack or compromised script, to achieve arbitrary file writes and potential data exposure.

Generated by OpenCVE AI on July 28, 2026 at 08:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the BOSH CLI to version 7.10.4 or later.
  • Limit the CLI’s execution to trusted users and validate or sanitize the path values in blobs.yml to reduce the risk of unintended file writes.
  • Disable the vulnerable blobs.yml path feature to prevent the tool from writing files outside the intended scope.

Generated by OpenCVE AI on July 28, 2026 at 08:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-22

Wed, 22 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-22

Thu, 16 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-22
CWE-788

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-22
CWE-788

Mon, 13 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-22
CWE-788

Sun, 12 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-22
CWE-788

Sat, 11 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
CWE-788

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
CWE-788

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Description The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.
Title blobs.yaml Path Traversal Allows File Writes
References
Metrics cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-07-09T14:10:24.256Z

Reserved: 2026-05-20T10:00:48.931Z

Link: CVE-2026-47826

cve-icon Vulnrichment

Updated: 2026-07-09T14:10:18.930Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:00:06Z

Weaknesses

No weakness.