CVE-2026-40162Disclosure(bugsink / bugsink)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugsink 2.1.0 in the artifact bundle assembly flow. A user with a valid authentication token could cause the application to write attacker-controlled content to a filesystem location writable by the Bugsink process. This vulnerability is fixed in 2.1.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bugsink

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-10); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
bugsink

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-10: 1Mentions · 2026-04-11: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-28: 104-1004-1104-28
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-101
Disclosure1
2026-04-111
Disclosure1
2026-04-281
General1
Full discourse3 posts
  • cvereports@_cvereports
    General

    CVE-2026-40162: CVE-2026-40162: Authenticated Arbitrary File Write in Bugsink Artifact Assembly An authenticated arbitrary file write vulnerability exists in Bugsink 2.1.0 within the artifact bundle assembly workflow. Attackers can leverage the `check... https://cvereports.com/reports/CVE-2026-40162

    Post summary

    The text provides a basic description of CVE-2026-40162 but lacks evidence of a PoC, exploit, active use, patch, or debunking.

    0000034
    36 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40162 Authenticated Arbitrary File Write Vulnerability in Bugsink 2.1.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40162

    Post summary

    A new authenticated arbitrary file write vulnerability (CVE-2026-40162) has been disclosed for Bugsink 2.1.0, with no mention of PoC, exploit code, active attacks, patches, or debunking.

    0000039
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40162 Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugsink 2.1.0 in the artifact bundle assembly flow… https://www.cve.org/CVERecord?id=CVE-2026-40162

    Post summary

    The passage announces CVE-2026-40162: an authenticated file‑write vulnerability in Bugsink v2.1.0’s artifact bundle assembly, without any PoC, exploit script, or patch details.

    00000108
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbugsinkbugsink2.1.0--

Explore more