CVE-2026-31886Disclosure(dagu / dagu)

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dagu dagu systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the inline DAG execution endpoints is passed directly into filepath.Join to construct a temporary directory path without any format validation. Go's filepath.Join resolves .. segments lexically, so a caller can supply a value such as ".." to redirect the computed directory outside the intended /tmp/<name>/<id> path. A deferred cleanup function that calls os.RemoveAll on that directory then runs unconditionally when the HTTP handler returns, deleting whatever directory the traversal resolved to. With dagRunId set to "..", the resolved directory is the system temporary directory (/tmp on Linux). On non-root deployments, os.RemoveAll("/tmp") removes all files in /tmp owned by the dagu process user, disrupting every concurrent dagu run that has live temp files. On root or Docker deployments, the call removes the entire contents of /tmp, causing a system-wide denial of service. This vulnerability is fixed in 2.2.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dagu

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-03-13); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
dagu

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-13: 3Mentions · 2026-03-14: 1Mentions · 2026-03-23: 1Patch / Workaround · 2026-03-13: 2Technical Details · 2026-03-13: 3Technical Details · 2026-03-14: 1Technical Details · 2026-03-23: 103-1303-1403-23
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-133
Disclosure2Patch1
2026-03-141
General1
2026-03-231
Disclosure1
Full discourse5 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical path traversal vulnerability (CVE-2026-31886) in `Dagu` via `dagRunId` could lead to unauthorized file access. Review `Dagu` configurations. #PathTraversal #SecurityAdvisory #Dagu https://www.pulsepatch.io/posts/cve-2026-31886-dagu-path-traversal

    Post summary

    The text announces a path traversal flaw (CVE‑2026‑31886) in Dagu that could allow unauthorized file access via dagRunId. No proof of concept, exploit code, or patch information is provided, and there is no indication of active exploitation.

    0000025
    2 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-31886 - Critical Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the inline DAG execution endpoints is passed directly into http://filepath.Jo... https://www.thehackerwire.com/vulnerability/CVE-2026-31886/ https://t.co/ybX7bRt65Y

    Post summary

    The tweet alerts about a critical CVE‑2026‑31886 in the Dagu workflow engine, noting a flaw involving the `dagRunId` field, but does not provide PoC, exploit, patch, or active use details.

    0000036
    135 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31886 Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the inline DAG execution endpoints is passed dire… https://www.cve.org/CVERecord?id=CVE-2026-31886

    Post summary

    The post discloses a flaw in Dagu's inline DAG execution where the dagRunId field is improperly processed before version 2.2.4, and notes that an update mitigates the issue.

    00000163
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-31886: CRITICAL] Dagu 2.2.4 fixes a vulnerability allowing malicious input (e.g., "..") in dagRunId, leading to directory traversal &amp; potential DoS attack. Update for cyber security.#cve,CVE-2026-31886,#cybersecurity https://cvefind.com/CVE-2026-31886

    Post summary

    The post announces the release of Dagu 2.2.4, which patches a critical directory‑traversal flaw (CVE‑2026‑31886) that could lead to denial‑of‑service attacks.

    0000055
    602 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-31886: Dagu has a Path Traversal via `d... Path traversal via `..` in dagRunId triggers `os.RemoveAll("/tmp")` on cleanup - instant system DoS when running as roo... https://zerodaysignal.com/vulnerability/CVE-2026-31886 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑31886 in Dagu, describing a path traversal that causes a system DoS by deleting /tmp, with no evidence of exploitation, PoC, or patch.

    0000067
    147 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdagudagu---

Explore more