CRITICAL 9.1 CVE-2026-51859 Published 30 Sept 2026

Bisheng Directory Traversal Vulnerability in File Download

Worried this affects your website?

Bisheng versions 2.3.0, 2.4.0, and 2.4.0-beta1 are vulnerable to a directory traversal issue in the save_download_file function in src/backend/bisheng/core/cache/utils.py.

An attacker could exploit this flaw to read files outside the intended download directory.

  • Affected versions: 2.3.0, 2.4.0, 2.4.0-beta1
  • Vulnerable location: src/backend/bisheng/core/cache/utils.py:290

Reference: CVE-2026-51859 on NVD

← Back to Security News