Description
bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Code Injection in src/backend/bisheng/api/v1/validate.py.
Published: 2026-09-30
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Bisheng version 2.3.0, 2.4.0, and 2.4.0‑beta1 contain a code injection flaw located in the validate.py module at src/backend/bisheng/api/v1/validate.py. The flaw allows an attacker to inject and execute arbitrary code through the API’s validate endpoint, potentially compromising the integrity and confidentiality of the system. Exploitation would enable the execution of malicious commands on the host running Bisheng, leading to full system compromise.

Affected Systems

The affected product is Bisheng, specifically versions 2.3.0, 2.4.0, and the beta release 2.4.0‑beta1. No vendor information is listed, but the software appears to be a web API component that processes user input on the validate endpoint.

Risk and Exploitability

No CVSS score is provided, and the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. Because the code injection flaw resides in a publicly exposed API endpoint, the risk of exploitation is high if the API is accessible from untrusted networks. Attackers could pass specially crafted input to the validate function to trigger execution of arbitrary code. The potential impact is full remote code execution on the underlying host.

Generated by OpenCVE AI on September 30, 2026 at 23:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Bisheng to the latest patched release that mitigates the code injection flaw.
  • If upgrade is not immediately possible, limit access to the /api/v1/validate endpoint to a trusted subnet or enforce strict authentication and authorization.
  • Implement input sanitization or remove dynamic code execution from the validate routine to reduce the attack surface.

Generated by OpenCVE AI on September 30, 2026 at 23:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Code Injection Vulnerability in Bisheng API Validate Endpoint
Weaknesses CWE-94

Wed, 30 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Code Injection in src/backend/bisheng/api/v1/validate.py.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T20:56:16.276Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51861

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:17:12.127

Modified: 2026-09-30T21:17:12.127

Link: CVE-2026-51861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T23:15:14Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')