CVE-2026-27614Disclosure(bugsink / bugsink)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch bugsink bugsink systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit events to a Bugsink project can store arbitrary JavaScript in an event. The payload executes only if a user explicitly views the affected Stacktrace in the web UI. When Pygments returns more lines than it was given (a known upstream quirk that triggers with Ruby heredoc-style input), `_pygmentize_lines()` in `theme/templatetags/issues.py:75-77` falls back to returning the raw input lines. `mark_safe()` at line 111-113 is then applied unconditionally - including to those unsanitized raw lines. Since DSN endpoints are public by Sentry protocol, no account is needed to inject. The payload sits in the database until an admin looks at the event. Successful exploitation requires that the attacker to be able to submit events to the project (i.e. knows the DSN or can access a client that uses it), the Bugsink ingest endpoint is reachable to the attacker, and an administrator explicitly views the crafted event in the UI. Under those conditions, the attacker can execute JavaScript in the administrator’s browser and act with that user’s privileges within Bugsink. Version 2.0.13 fixes the vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bugsink

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-02-25); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
bugsink

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-25: 3Mentions · 2026-03-02: 1Patch / Workaround · 2026-02-25: 1Technical Details · 2026-02-25: 3Technical Details · 2026-03-02: 102-2503-02
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-253
Disclosure2Patch1
2026-03-021
General1
Full discourse4 posts
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-27614 (CVSS:9.3, CRITICAL) is Analyzed. Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit ev..https://nvd.nist.gov/vuln/detail/CVE-2026-27614 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE‑2026‑27614, noting its critical severity and that unauthenticated attackers can submit data in Bugsink versions before 2.0.13, but provides no PoC, exploit code, or patch details.

    0000029
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27614 Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit events to a Bugsink project can store arbitrary … https://www.cve.org/CVERecord?id=CVE-2026-27614

    Post summary

    The CVE-2026-27614 disclosure notes that unauthenticated attackers can store arbitrary data in Bugsink before version 2.0.13, but no PoC, exploit, or patch details are included.

    00000115
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27614: CRITICAL] Vulnerability alert: Bugsink error tracking tool versions < 2.0.13 allow unauthenticated attackers to execute JavaScript. Update to version 2.0.13 to patch this security flaw.#cve,CVE-2026-27614,#cybersecurity https://cvefind.com/CVE-2026-27614

    Post summary

    The post announces a critical vulnerability in Bugsink error tracking tool, highlights that unauthenticated attackers can execute JavaScript, and urges users to update to version 2.0.13 to remediate the flaw.

    0000068
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27614** pertains to a critical security flaw in **Bugsink**, a self-hosted error tracking tool. The vulnerability allows **unauthenticated attackers** to inject malicious JavaScript payloads into the system, which are only executed when an administrator views specific event details in the web UI. This results in **stored cross-site scripting (XSS)**, enabling attackers to execute arbitrary scripts within the context of an administrator's browser. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #XSS https://cvetodo.com/cve/CVE-2026-27614

    Post summary

    CVE-2026-27614 is a stored cross‑site scripting flaw in Bugsink that lets unauthenticated attackers inject JavaScript, which runs when an administrator views event details in the web UI.

    0000049
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbugsinkbugsink---

Explore more