CVE-2026-40162: Bugsink affected by authenticated arbitrary file write in artifactbundle/assemble
An authenticated file write vulnerability was identified in Bugsink 2.1.0 in the artifact bundle assembly flow.
A user with a valid authentication token could cause the application to write attacker-controlled content to a filesystem location writable by the Bugsink process.
This issue requires authentication and affects only version 2.1.0.
The issue is fixed in 2.1.1.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-40162 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →