Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. bugsink
  4. ›
  5. CVE-2026-47728

CVE-2026-47728: Bugsink: Project scoping missing in sourcemap and debug-file lookup

June 5, 2026

Bugsink before 2.2.0 resolved sourcemaps and debug files by debug ID without scoping that lookup to the project that owned the uploaded metadata. An authenticated user with access to one project could cause event processing in that project to use sourcemap/debug-file metadata uploaded for another project in the same Bugsink instance, if the same debug ID was referenced.

References

  • github.com/advisories/GHSA-5389-f7vh-wxj8
  • github.com/bugsink/bugsink/releases/tag/2.2.0
  • github.com/bugsink/bugsink/security/advisories/GHSA-5389-f7vh-wxj8
  • nvd.nist.gov/vuln/detail/CVE-2026-47728

Code Behaviors & Features

Detect and mitigate CVE-2026-47728 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.2.0

Fixed versions

  • 2.2.0

Solution

Upgrade to version 2.2.0 or above.

Impact 4.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-862: Missing Authorization

Source file

pypi/bugsink/CVE-2026-47728.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:23:25 +0000.