Description
bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to directory traversal in save_download_file (src/backend/bisheng/core/cache/utils.py:290).
Published: 2026-09-30
Score: n/a
EPSS: n/a
KEV: No
Impact: Directory traversal allowing unauthorized file access
Action: Immediate Update
AI Analysis

Impact

bisheng version 2.3.0, 2.4.0, and 2.4.0-beta1 suffers a directory traversal flaw in the save_download_file routine defined in src/backend/bisheng/core/cache/utils.py:290. An attacker supplied path can cause the function to save or read files outside the intended cache directory, potentially exposing sensitive system files or allowing the creation of arbitrary files. This flaw is a classic path traversal vulnerability and can lead to information disclosure, modification, or execution of unintended content.

Affected Systems

Authorized users of the bisheng software, specifically those running the 2.3.0 and 2.4.0 series including the beta release, are at risk. The structural change resides in the cache utility used for downloading files within the application.

Risk and Exploitability

No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, indicating that publicly known exploitation is not documented. The CVSS score is not provided, but the directory traversal flaw could be exploited remotely if the save_download_file endpoint is exposed over a network connection. Based on the description, the likely attack vector is remote via a web or API interface that accepts file download requests; however, the exact vector is not detailed in the advisory. The absence of a KEV listing suggests the threat level is moderate pending further observation of exploitation activity.

Generated by OpenCVE AI on September 30, 2026 at 23:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest bisheng release that contains the directory traversal fix.
  • If an upgrade is infeasible, validate the supplied file path to ensure it remains inside the cache directory, rejecting any traversal sequences before invoking save_download_file.
  • Limit the use of save_download_file to trusted users or environments by enforcing strict access controls and disabling the feature for unauthenticated or low‑privilege clients.

Generated by OpenCVE AI on September 30, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Directory Traversal in bisheng Cache Utility Exposes Unauthorized File Access
Weaknesses CWE-22

Wed, 30 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to directory traversal in save_download_file (src/backend/bisheng/core/cache/utils.py:290).
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T20:54:08.685Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51859

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:17:11.893

Modified: 2026-09-30T21:17:11.893

Link: CVE-2026-51859

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T23:15:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')