CVE 3.1 LOW

Bugsink: Issue event views can show an event from another project if its UUID is known_CVE-2026-47715

3.1 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier from the URL and, in affected versions, look up that event without also requiring it to belong to the issue in the URL. This is a project-boundary authorization issue: a logged-in user with access to one project can view another project’s event data through an issue they are allowed to access. The affected views include the stacktrace, details, and breadcrumbs pages for an issue event. This vulnerability is fixed in 2.2.0.

Basic Information

ID CVE-2026-47715
Source GitHub_M
Published May 26, 2026 at 16:22

Affected Product

Vendor bugsink
Product bugsink
Version < 2.2.0
Affected Versions bugsink bugsink < 2.2.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.