PT-2026-83301 · Bisheng · Bisheng

·

CVE-2026-82278

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BISHENG versions prior to 2.6.0
Description Authenticated users can achieve remote code execution by submitting crafted Code node definitions to the 'POST /api/v1/workflow/run once' endpoint. The system processes these definitions using the exec() function without sandboxing, which allows the execution of arbitrary Python code. This can lead to unauthorized access to the filesystem, credentials, and internal network resources.
Recommendations Update BISHENG to version 2.6.0 or later. As a temporary mitigation, restrict access to the 'POST /api/v1/workflow/run once' endpoint.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82278

Affected Products

Bisheng