CRITICAL
9.1 CVE-2026-51859 Published 30 Sept 2026
Bisheng Directory Traversal Vulnerability in File Download
Worried this affects your website?
Bisheng versions 2.3.0, 2.4.0, and 2.4.0-beta1 are vulnerable to a directory traversal issue in the save_download_file function in src/backend/bisheng/core/cache/utils.py.
An attacker could exploit this flaw to read files outside the intended download directory.
- Affected versions: 2.3.0, 2.4.0, 2.4.0-beta1
- Vulnerable location: src/backend/bisheng/core/cache/utils.py:290
Reference: CVE-2026-51859 on NVD
← Back to Security News