PT-2026-83301 · Bisheng · Bisheng
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BISHENG versions prior to 2.6.0
Description
Authenticated users can achieve remote code execution by submitting crafted Code node definitions to the 'POST /api/v1/workflow/run once' endpoint. The system processes these definitions using the
exec() function without sandboxing, which allows the execution of arbitrary Python code. This can lead to unauthorized access to the filesystem, credentials, and internal network resources.Recommendations
Update BISHENG to version 2.6.0 or later.
As a temporary mitigation, restrict access to the 'POST /api/v1/workflow/run once' endpoint.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bisheng