Product
Authenticated users can achieve remote code execution in BISHENG versions prior to 2.6.0 by submitting crafted Python payloads to the /api/v1/workflow/run_once endpoint.