CVE-2026-51859

Published: Set 30, 2026 Last Modified: Set 30, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to directory traversal in save_download_file (src/backend/bisheng/core/cache/utils.py:290).

https://gist.github.com/Ro1ME/df160925a60dd917550f7c87bfe62519
https://github.com/dataelement/bisheng/issues/1994