
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27598 is a path traversal vulnerability in Dagu, a workflow engine with a built-in web UI, affecting all versions up to and including 1.16.7. The flaw exists in the CreateNewDAG API endpoint (POST /api/v1/dags), which fails to validate the DAG name before passing it to the file store, allowing an authenticated user with DAG write permissions to write arbitrary YAML files anywhere on the filesystem accessible to the Dagu process. The vulnerability was published on February 21, 2026, and assigned CVE-2026-27598. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 7.1 (High) (GitHub Advisory, Feedly).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). While the RenameDAG handler correctly calls core.ValidateDAGName() to reject names containing path separators, the CreateNewDAG handler (internal/service/frontend/api/v1/dags.go, lines 120–170) omits this validation entirely and passes user input directly to dagStore.Create(). In internal/persis/filedag/store.go, the generateFilePath function (lines 493–498) detects path separators in the name and resolves the path via filepath.Abs(name), which completely ignores the configured baseDir. As a result, a DAG name such as ../../tmp/pwned causes the file to be written to /tmp/pwned.yaml rather than the intended DAGs directory. The fix (commit e2ed589) adds ValidateDAGName() to the CreateNewDAG handler and rewrites generateFilePath to use filepath.Base() and verify the resolved path stays within baseDir (GitHub Advisory, Patch Commit).
An authenticated user with DAG write permissions can write attacker-controlled YAML content to any filesystem location writable by the Dagu process, bypassing the intended DAGs directory restriction. Because Dagu executes DAG files as shell commands, an attacker can achieve remote code execution by writing a malicious DAG to the DAGs directory of another Dagu instance or by overwriting configuration files. The primary impact is high integrity loss; confidentiality and availability are not directly impacted by the write primitive alone, but the potential for RCE significantly elevates the overall risk (GitHub Advisory, Feedly).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory (GHSA-6v48-fcq6-ff23) as a simple curl command, making the vulnerability straightforward to reproduce. Exploitation requires authentication with DAG write permissions, which limits the attack surface compared to unauthenticated vulnerabilities. There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.39% (0.151% per GitHub Advisory), placing it in the lower percentiles for near-term exploitation probability (GitHub Advisory, Feedly).
/tmp/pwned, another Dagu instance's DAGs directory, or a configuration file), relative to the Dagu process working directory./api/v1/dags with a DAG name containing path traversal sequences and attacker-controlled YAML content:curl -X POST http://<target>:8080/api/v1/dags \
-H "Content-Type: application/json" \
-d '{
"name": "../../tmp/path-traversal-proof",
"spec": "steps:\n - command: id > /tmp/pwned\n"
}'generateFilePath function resolves the traversal sequence via filepath.Abs(), ignoring baseDir, and writes the YAML file to /tmp/path-traversal-proof.yaml with the Dagu process's permissions./api/v1/dags with name fields containing path separator characters (/, .., ../../) in API access logs./tmp/, /etc/, or other writable system directories) with .yaml extensions and DAG-like content (steps:, command:).POST /api/v1/dags requests with unusual or encoded DAG names; HTTP 200 responses to requests with traversal sequences in the name field (on unpatched versions)./bin/sh, bash, id, curl, wget) (GitHub Advisory).Upgrade Dagu to a version beyond 1.16.7 that includes the fix from commit e2ed589105d79273e4e6ac8eb31525f765bb3ce4, which adds ValidateDAGName() validation to the CreateNewDAG endpoint and hardens generateFilePath to prevent path traversal. As interim mitigations, restrict DAG write permissions to trusted users only, apply the principle of least privilege by running Dagu with minimal filesystem permissions, and restrict network access to the Dagu API endpoint. Monitor and audit API calls to /api/v1/dags for suspicious DAG names containing path separators or traversal sequences (GitHub Advisory, Patch Commit).
The vulnerability was published by the Dagu maintainer (yohamta0) via GitHub Security Advisory on February 21, 2026, and subsequently picked up by automated vulnerability tracking feeds including Vulners, CVEFeed, and CIRCL. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."