CVE-2025-54433

HIGH

Pypi Bugsink < 1.7.4 - Path Traversal

Title source: rule
STIX 2.1

Description

Bugsink is a self-hosted error tracking service. In versions 1.4.2 and below, 1.5.0 through 1.5.4, 1.6.0 through 1.6.3, and 1.7.0 through 1.7.3, ingestion paths construct file locations directly from untrusted event_id input without validation. A specially crafted event_id can result in paths outside the intended directory, potentially allowing file overwrite or creation in arbitrary locations. Submitting such input requires access to a valid DSN, potentially exposing them. If Bugsink runs in a container, the effect is confined to the container’s filesystem. In non-containerized setups, the overwrite may affect other parts of the system accessible to that user. This is fixed in versions 1.4.3, 1.5.5, 1.6.4 and 1.7.4.

Scores

CVSS v4 7.2
EPSS 0.0033
EPSS Percentile 55.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (5)
bugsink/bugsink < 1.4.3
bugsink/bugsink >= 1.5.0, < 1.5.5
bugsink/bugsink >= 1.6.0, < 1.6.4
bugsink/bugsink >= 1.7.0, < 1.7.4
pypi/bugsink 1.7.0 - 1.7.4PyPI
Published Jul 30, 2025
Tracked Since Feb 18, 2026