Bugsink Cross-Project Authorization Vulnerability in Issue Bulk Actions

Vulnerability

A cross-project authorization vulnerability has been identified in Bugsink, a self-hosted error tracking tool, prior to version 2.2.0. In affected versions, the issue list view authorizes access based on the project specified in the URL but allows bulk actions to be applied to issue IDs from different projects. This vulnerability requires authentication and knowledge of a valid issue UUID, but is considered low severity due to the lack of an issue enumeration path and the common single trust domain of self-hosted Bugsink instances.

Impact

Exploitation of this vulnerability allows for unauthorized cross-project modification of issue states, such as resolving or muting issues, within Bugsink. This could lead to confusion or mismanagement of issues across projects.

Remediation

Users can upgrade to Bugsink version 2.2.0 or later, where this vulnerability has been fixed. Instructions for downloading the latest version are available on the Bugsink GitHub releases page.

Added: May 26, 2026, 11:06 PM
Updated: May 26, 2026, 11:06 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.8
remediation
0.0
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.