CVE-2026-40162 Details
Description
Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugsink 2.1.0 in the artifact bundle assembly flow. A user with a valid authentication token could cause the application to write attacker-controlled content to a filesystem location writable by the Bugsink process. This vulnerability is fixed in 2.1.1.
An authenticated file write vulnerability has been identified in Bugsink version 2.1.0, specifically within the artifact bundle assembly process. This vulnerability allows users with a valid authentication token to manipulate the application into writing content controlled by the attacker to a filesystem location that is writable by the Bugsink process. The issue is present only in version 2.1.0 and has been addressed in the subsequent release, version 2.1.1.
Users are advised to upgrade to Bugsink version 2.1.1. Additionally, as a defense-in-depth measure, ensure that the Bugsink process operates with the minimum necessary filesystem permissions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bugsink/bugsink/releases/tag/2.1.1 | [email protected] | ProductRelease Notes |
| https://github.com/bugsink/bugsink/security/advisories/GHSA-8hw4-fhww-273g | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| bugsink bugsink | 2.1.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2026 | Initial Analysis | [email protected] |
| Apr 10, 2026 | New CVE Received | [email protected] |