Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23153 | Bugsink path traversal via event_id in ingestion |
Github GHSA |
GHSA-q78p-g86f-jg6q | Bugsink path traversal via event_id in ingestion |
Thu, 31 Jul 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bugsink
Bugsink bugsink |
|
| Vendors & Products |
Bugsink
Bugsink bugsink |
Wed, 30 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bugsink is a self-hosted error tracking service. In versions 1.4.2 and below, 1.5.0 through 1.5.4, 1.6.0 through 1.6.3, and 1.7.0 through 1.7.3, ingestion paths construct file locations directly from untrusted event_id input without validation. A specially crafted event_id can result in paths outside the intended directory, potentially allowing file overwrite or creation in arbitrary locations. Submitting such input requires access to a valid DSN, potentially exposing them. If Bugsink runs in a container, the effect is confined to the container’s filesystem. In non-containerized setups, the overwrite may affect other parts of the system accessible to that user. This is fixed in versions 1.4.3, 1.5.5, 1.6.4 and 1.7.4. | |
| Title | Bugsink is vulnerable to Path Traversal attacks via event_id in ingestion | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-30T14:46:51.691Z
Reserved: 2025-07-21T23:18:10.282Z
Link: CVE-2025-54433
Updated: 2025-07-30T14:40:04.737Z
Status : Deferred
Published: 2025-07-30T15:15:35.493
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-54433
No data.
OpenCVE Enrichment
Updated: 2025-07-31T10:09:16Z
EUVD
Github GHSA