CVE-2025-54433: Bugsink
High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.
Bugsink is a self-hosted error tracking service. In versions 1.4.2 and below, 1.5.0 through 1.5.4, 1.6.0 through 1.6.3, and 1.7.0 through 1.7.3, ingestion paths construct file locations directly from untrusted event_id input without validation. A specially crafted event_id can result in paths outside the intended directory, potentially allowing file overwrite or creation in arbitrary locations. Submitting such input requires access to a valid DSN, potentially exposing them. If Bugsink runs in a container, the effect is confined to the container’s filesystem. In non-containerized setups, the overwrite may affect other parts of the system accessible to that user. This is fixed in versions 1.4.3, 1.5.5, 1.6.4 and 1.7.4.
Affected products
- Bugsink Bugsink: from 1.7.0, before 1.7.4 (fixed in 1.7.4); from 1.6.0, before 1.6.4 (fixed in 1.6.4); from 1.5.0, before 1.5.5 (fixed in 1.5.5); before 1.4.3 (fixed in 1.4.3)
Published 2025-07-30. Last modified 2026-06-17.