External Control of File Name or Path Affecting bugsink package, versions [,2.1.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.3% (22nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-BUGSINK-15990748
  • published12 Apr 2026
  • disclosed10 Apr 2026
  • creditDongyangLyu Fullmoon

Introduced: 10 Apr 2026

CVE-2026-40162  (opens in a new tab)
CWE-73  (opens in a new tab)

How to fix?

Upgrade bugsink to version 2.1.1 or higher.

Overview

bugsink is a Self-hosted Error Tracking

Affected versions of this package are vulnerable to External Control of File Name or Path in the artifactbundle/assemble endpoint. An authenticated attacker can create or overwrite files within locations writable by the service account by supplying crafted input after authenticating. This may result in modification or corruption of application data, uploaded assets or temporary files, and could disrupt normal application behavior. The impact depends on the deployment environment and the filesystem permissions of the running process.

CVSS Base Scores

version 4.0
version 3.1