PatchSiren

dataelement CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH dataelement CVE published 2026-08-28

CVE-2026-82278

CVE-2026-82278 is a high-severity vulnerability in BISHENG, a workflow management system, which allows authenticated users to execute arbitrary Python code via the workflow run_once endpoint. The vulnerability exists due to the lack of sandboxing when executing Code node definitions submitted through the POST /api/v1/workflow/run_once endpoint. Successful exploitation could allow attackers to gain access [truncated]