Impact
Bisheng version 2.3.0, 2.4.0, and 2.4.0‑beta1 contain a code injection flaw located in the validate.py module at src/backend/bisheng/api/v1/validate.py. The flaw allows an attacker to inject and execute arbitrary code through the API’s validate endpoint, potentially compromising the integrity and confidentiality of the system. Exploitation would enable the execution of malicious commands on the host running Bisheng, leading to full system compromise.
Affected Systems
The affected product is Bisheng, specifically versions 2.3.0, 2.4.0, and the beta release 2.4.0‑beta1. No vendor information is listed, but the software appears to be a web API component that processes user input on the validate endpoint.
Risk and Exploitability
No CVSS score is provided, and the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. Because the code injection flaw resides in a publicly exposed API endpoint, the risk of exploitation is high if the API is accessible from untrusted networks. Attackers could pass specially crafted input to the validate function to trigger execution of arbitrary code. The potential impact is full remote code execution on the underlying host.
OpenCVE Enrichment