CVE-2026-47728 Details
Description
Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID without scoping that lookup to the project that owned the uploaded metadata. An authenticated user with access to one project could cause event processing in that project to use sourcemap/debug-file metadata uploaded for another project in the same Bugsink instance, if the same debug ID was referenced. This vulnerability is fixed in 2.2.0.
A vulnerability in Bugsink, a self-hosted error tracking tool, prior to version 2.2.0, allowed for the improper resolution of sourcemaps and debug files. The issue arose because the lookup was not scoped to the project that owned the uploaded metadata. This flaw enabled an authenticated user with access to one project to cause event processing in that project to utilize sourcemap or debug-file metadata from another project within the same Bugsink instance, provided that the same debug ID was referenced. The vulnerability could lead to the unintentional disclosure of source context or symbolication-derived information from another project.
Users can upgrade to Bugsink version 2.2.0 or later to address this vulnerability. After upgrading, it is recommended to upload sourcemaps and debug files with the appropriate project information. To remove legacy projectless sourcemap metadata immediately after upgrading, the command 'bugsink-manage delete_legacy_sourcemaps' can be used.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 26, 2026CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bugsink/bugsink/releases/tag/2.2.0 | [email protected] | Release NotesVendor |
| https://github.com/bugsink/bugsink/security/advisories/GHSA-5389-f7vh-wxj8 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Bugsink | <= 2.1.3 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | New CVE Received | [email protected] |
Volerion