Bugsink Cross-Project Authorization Vulnerability Allowing Event Data Exposure

Vulnerability

A project-boundary authorization vulnerability has been identified in Bugsink, a self-hosted error tracking tool, prior to version 2.2.0. The issue arises because the issue event pages accept a direct event identifier from the URL and, in affected versions, retrieve that event without ensuring it belongs to the issue specified in the URL. This flaw allows a logged-in user with access to one project to view event data from another project through an issue they can access. The exposed event data includes stack traces, details, and breadcrumbs. The vulnerability requires authentication and prior knowledge of a valid event UUID, but is considered low severity due to the lack of an event enumeration path and the common practice of self-hosting Bugsink within a single trust domain.

Impact

Exploitation of this vulnerability leads to unauthorized cross-project event data exposure, allowing a user to access event information from other projects they should not have visibility into.

Remediation

Users can upgrade to Bugsink version 2.2.0 or later, where this vulnerability has been fixed. Instructions for downloading the latest version are available on the Bugsink GitHub Releases page.

Added: May 26, 2026, 11:06 PM
Updated: May 26, 2026, 11:06 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.8
remediation
0.0
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.