← back
CVE-2026-27598

Dagu: Path traversal in DAG creation allows arbitrary YAML file write outside DAGs directory

CVSS 7.1 HIGHEPSS 0.6%CWE-22
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.1EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
25 Feb 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Dagu is a workflow engine with a built-in Web user interface. In versions up to and including 1.16.7, the `CreateNewDAG` API endpoint (`POST /api/v1/dags`) does not validate the DAG name before passing it to the file store. An authenticated user with DAG write permissions can write arbitrary YAML files anywhere on the filesystem (limited by the process permissions). Since dagu executes DAG files as shell commands, writing a malicious DAG to the DAGs directory of another instance or overwriting config files can lead to remote code execution. Commit e2ed589105d79273e4e6ac8eb31525f765bb3ce4 fixes the issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
dagu-org · dagu

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →