High severity8.8NVD Advisory· Published Aug 28, 2026
CVE-2026-82278
CVE-2026-82278
Description
BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can submit crafted Code node definitions to the POST /api/v1/workflow/run_once endpoint, which executes them with exec() without sandboxing, gaining access to filesystem, credentials, and internal network resources.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <2.6.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.