CVE-2025-54433High▾ TwilightBugsink path traversal via event_id in ingestion
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
0.5% → 0.6%
In affected versions, ingestion paths construct file locations directly from untrusted event_id input without validation. A specially crafted event_id can result in paths outside the intended directory, potentially allowing file overwrite or creation in arbitrary locations.
Submitting such input requires access to a valid DSN. While that limits exposure, DSNs are sometimes discoverable—for example, when included in frontend code—and should not be treated as a strong security boundary.
A valid DSN holder can craft an event_id that causes the ingestion process to write files outside its designated directory. This allows overwriting files accessible to the user running Bugsink.
If Bugsink runs in a container, the effect is confined to the container’s filesystem. In non-containerized setups, the overwrite may affect other parts of the system accessible to that user.
Update to version 1.7.4, 1.6.4, 1.5.5 or 1.4.3 , which require event_id to be a valid UUID and normalizes it before use in file paths.
bugsink >= 1.7.0, < 1.7.4bugsink >= 1.6.0, < 1.6.4bugsink >= 1.5.0, < 1.5.5bugsink < 1.4.3Upgrade to a patched release:
bugsink 1.7.4bugsink 1.6.4bugsink 1.5.5bugsink 1.4.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-47715Low· 3.1Bugsink: Issue event views can show an event from another project if its UUID is known
CVE-2026-47716Low· 3.1Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known
CVE-2026-44502Medium· 4.3Bunsink has an SSRF bypass in `validate_webhook_url`
CVE-2026-40162High· 7.1Bugsink affected by authenticated arbitrary file write in artifactbundle/assemble
CVE-2026-53954Medium· 4.3Bugsink is a self-hosted error tracking tool
CVE-2026-47728Medium· 4.3Bugsink: Project scoping missing in sourcemap and debug-file lookup