Impact
bisheng version 2.3.0, 2.4.0, and 2.4.0-beta1 suffers a directory traversal flaw in the save_download_file routine defined in src/backend/bisheng/core/cache/utils.py:290. An attacker supplied path can cause the function to save or read files outside the intended cache directory, potentially exposing sensitive system files or allowing the creation of arbitrary files. This flaw is a classic path traversal vulnerability and can lead to information disclosure, modification, or execution of unintended content.
Affected Systems
Authorized users of the bisheng software, specifically those running the 2.3.0 and 2.4.0 series including the beta release, are at risk. The structural change resides in the cache utility used for downloading files within the application.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, indicating that publicly known exploitation is not documented. The CVSS score is not provided, but the directory traversal flaw could be exploited remotely if the save_download_file endpoint is exposed over a network connection. Based on the description, the likely attack vector is remote via a web or API interface that accepts file download requests; however, the exact vector is not detailed in the advisory. The absence of a KEV listing suggests the threat level is moderate pending further observation of exploitation activity.
OpenCVE Enrichment