HIGH
dataelement
CVE published 2026-08-28
CVE-2026-82278
CVE-2026-82278 is a high-severity vulnerability in BISHENG, a workflow management system, which allows authenticated users to execute arbitrary Python code via the workflow run_once endpoint. The vulnerability exists due to the lack of sandboxing when executing Code node definitions submitted through the POST /api/v1/workflow/run_once endpoint. Successful exploitation could allow attackers to gain access [truncated]