CVE-2026-27598Disclosure(dagu / dagu)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Dagu is a workflow engine with a built-in Web user interface. In versions up to and including 1.16.7, the `CreateNewDAG` API endpoint (`POST /api/v1/dags`) does not validate the DAG name before passing it to the file store. An authenticated user with DAG write permissions can write arbitrary YAML files anywhere on the filesystem (limited by the process permissions). Since dagu executes DAG files as shell commands, writing a malicious DAG to the DAGs directory of another instance or overwriting config files can lead to remote code execution. Commit e2ed589105d79273e4e6ac8eb31525f765bb3ce4 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dagu

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-25); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
dagu

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-25: 3Mentions · 2026-03-24: 1Technical Details · 2026-02-25: 302-2503-24
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-253
Disclosure2General1
2026-03-241
General1
Full discourse4 posts
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-33344 - High Dagu is a workflow engine with a built-in Web user interface. From version 2.0.0 to before version 2.3.1, the fix for CVE-2026-27598 added ValidateDAGName to CreateNewDAG and rewrote generate... https://www.thehackerwire.com/vulnerability/CVE-2026-33344/ https://t.co/865P9uaKWn

    Post summary

    The post merely notes the high severity of CVE‑2026‑33344 and links to an external source, providing no substantive technical or exploit information.

    0000026
    145 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-27598 Dagu is a workflow engine with a built-in Web user interface. In versions up to and including 1.16.7, the `CreateNewDAG` API endpoint (`POST /api/v1/dags`) does not v… https://www.cve.org/CVERecord?id=CVE-2026-27598 ----- Traducción: CVE-2026-27598 Dag… http://infoflow.cloud`

    Post summary

    The post references CVE‑2026‑27598, noting a flaw in Dagu’s CreateNewDAG API endpoint for versions up to 1.16.7, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000035
    54 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27598 Dagu is a workflow engine with a built-in Web user interface. In versions up to and including 1.16.7, the `CreateNewDAG` API endpoint (`POST /api/v1/dags`) does not v… https://www.cve.org/CVERecord?id=CVE-2026-27598

    Post summary

    The snippet references CVE-2026-27598 for Dagu, noting a flaw in the CreateNewDAG API endpoint in versions up to 1.16.7, but provides no PoC, exploit, or patch details.

    00000141
    56.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27598: Dagu Path Traversal: When 'Absolute' Power Corrupts Absolutely A critical Path Traversal vulnerability in the Dagu workflow engine allows attackers to break out of the intended storage directory. By manipulating the DAG name in the API... https://cvereports.com/reports/CVE-2026-27598

    Post summary

    The post announces a critical path traversal vulnerability in the Dagu workflow engine that lets attackers escape the intended storage directory by manipulating the DAG name via the API.

    0000051
    31 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdagudagu---

Explore more