CVE Database
/

CVE-2025-54433

Back to search

CVE-2025-54433

Published: Jul 30, 2025

Modified: Jul 30, 2025

PUBLISHED

Description

Bugsink is a self-hosted error tracking service. In versions 1.4.2 and below, 1.5.0 through 1.5.4, 1.6.0 through 1.6.3, and 1.7.0 through 1.7.3, ingestion paths construct file locations directly from untrusted event_id input without validation. A specially crafted event_id can result in paths outside the intended directory, potentially allowing file overwrite or creation in arbitrary locations. Submitting such input requires access to a valid DSN, potentially exposing them. If Bugsink runs in a container, the effect is confined to the container’s filesystem. In non-containerized setups, the overwrite may affect other parts of the system accessible to that user. This is fixed in versions 1.4.3, 1.5.5, 1.6.4 and 1.7.4.

VendorProductVersions

bugsink

bugsink

affected
>= 1.7.0, < 1.7.4
affected
>= 1.6.0, < 1.6.4
affected
>= 1.5.0, < 1.5.5
affected
< 1.4.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now