Vulnerability Description
Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugsink 2.1.0 in the artifact bundle assembly flow. A user with a valid authentication token could cause the application to write attacker-controlled content to a filesystem location writable by the Bugsink process. This vulnerability is fixed in 2.1.1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bugsink | Bugsink | 2.1.0 |
Related Weaknesses (CWE)
References
- https://github.com/bugsink/bugsink/releases/tag/2.1.1ProductRelease Notes
- https://github.com/bugsink/bugsink/security/advisories/GHSA-8hw4-fhww-273gMitigationVendor Advisory
FAQ
What is CVE-2026-40162?
CVE-2026-40162 is a vulnerability with a CVSS score of 7.1 (HIGH). Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugsink 2.1.0 in the artifact bundle assembly flow. A user with a valid authenticati...
How severe is CVE-2026-40162?
CVE-2026-40162 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-40162?
Check the references section above for vendor advisories and patch information. Affected products include: Bugsink Bugsink.