CVE-2026-27598: 
Homebrew vulnerability analysis and mitigation

Overview

CVE-2026-27598 is a path traversal vulnerability in Dagu, a workflow engine with a built-in web UI, affecting all versions up to and including 1.16.7. The flaw exists in the CreateNewDAG API endpoint (POST /api/v1/dags), which fails to validate the DAG name before passing it to the file store, allowing an authenticated user with DAG write permissions to write arbitrary YAML files anywhere on the filesystem accessible to the Dagu process. The vulnerability was published on February 21, 2026, and assigned CVE-2026-27598. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 7.1 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). While the RenameDAG handler correctly calls core.ValidateDAGName() to reject names containing path separators, the CreateNewDAG handler (internal/service/frontend/api/v1/dags.go, lines 120–170) omits this validation entirely and passes user input directly to dagStore.Create(). In internal/persis/filedag/store.go, the generateFilePath function (lines 493–498) detects path separators in the name and resolves the path via filepath.Abs(name), which completely ignores the configured baseDir. As a result, a DAG name such as ../../tmp/pwned causes the file to be written to /tmp/pwned.yaml rather than the intended DAGs directory. The fix (commit e2ed589) adds ValidateDAGName() to the CreateNewDAG handler and rewrites generateFilePath to use filepath.Base() and verify the resolved path stays within baseDir (GitHub Advisory, Patch Commit).

Impact

An authenticated user with DAG write permissions can write attacker-controlled YAML content to any filesystem location writable by the Dagu process, bypassing the intended DAGs directory restriction. Because Dagu executes DAG files as shell commands, an attacker can achieve remote code execution by writing a malicious DAG to the DAGs directory of another Dagu instance or by overwriting configuration files. The primary impact is high integrity loss; confidentiality and availability are not directly impacted by the write primitive alone, but the potential for RCE significantly elevates the overall risk (GitHub Advisory, Feedly).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory (GHSA-6v48-fcq6-ff23) as a simple curl command, making the vulnerability straightforward to reproduce. Exploitation requires authentication with DAG write permissions, which limits the attack surface compared to unauthenticated vulnerabilities. There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.39% (0.151% per GitHub Advisory), placing it in the lower percentiles for near-term exploitation probability (GitHub Advisory, Feedly).

Exploitation steps

  1. Authenticate: Obtain valid credentials for a Dagu instance (version ≤ 1.16.7) with DAG write permissions.
  2. Identify target path: Determine a target filesystem path to overwrite or create a file (e.g., /tmp/pwned, another Dagu instance's DAGs directory, or a configuration file), relative to the Dagu process working directory.
  3. Craft malicious request: Construct a POST request to /api/v1/dags with a DAG name containing path traversal sequences and attacker-controlled YAML content:
curl -X POST http://<target>:8080/api/v1/dags \
  -H "Content-Type: application/json" \
  -d '{
    "name": "../../tmp/path-traversal-proof",
    "spec": "steps:\n  - command: id > /tmp/pwned\n"
  }'
  1. File written: The generateFilePath function resolves the traversal sequence via filepath.Abs(), ignoring baseDir, and writes the YAML file to /tmp/path-traversal-proof.yaml with the Dagu process's permissions.
  2. Achieve RCE (optional): If the written file lands in a DAGs directory monitored by a Dagu instance, trigger execution of the malicious DAG via the Dagu API or scheduler to execute arbitrary shell commands (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /api/v1/dags with name fields containing path separator characters (/, .., ../../) in API access logs.
  • File System: YAML files appearing outside the configured Dagu DAGs directory (e.g., in /tmp/, /etc/, or other writable system directories) with .yaml extensions and DAG-like content (steps:, command:).
  • Logs: Dagu API access logs showing POST /api/v1/dags requests with unusual or encoded DAG names; HTTP 200 responses to requests with traversal sequences in the name field (on unpatched versions).
  • Process: Unexpected child processes spawned by the Dagu process executing commands from DAG files written to non-standard locations (e.g., /bin/sh, bash, id, curl, wget) (GitHub Advisory).

Mitigation and workarounds

Upgrade Dagu to a version beyond 1.16.7 that includes the fix from commit e2ed589105d79273e4e6ac8eb31525f765bb3ce4, which adds ValidateDAGName() validation to the CreateNewDAG endpoint and hardens generateFilePath to prevent path traversal. As interim mitigations, restrict DAG write permissions to trusted users only, apply the principle of least privilege by running Dagu with minimal filesystem permissions, and restrict network access to the Dagu API endpoint. Monitor and audit API calls to /api/v1/dags for suspicious DAG names containing path separators or traversal sequences (GitHub Advisory, Patch Commit).

Community reactions

The vulnerability was published by the Dagu maintainer (yohamta0) via GitHub Security Advisory on February 21, 2026, and subsequently picked up by automated vulnerability tracking feeds including Vulners, CVEFeed, and CIRCL. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database aggregation.

Additional resources


Source: This report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-100266MEDIUM6.5
  • NixOS logoNixOS
  • hub
NoYesSep 30, 2026
CVE-2026-100265MEDIUM6.5
  • NixOS logoNixOS
  • rider
NoYesSep 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management