Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Runtipi
Runtipi runtipi |
|
| Vendors & Products |
Runtipi
Runtipi runtipi |
Fri, 21 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-controlled backup archive and copies them into live application paths during the backup restore flow. An authenticated attacker can plant user-config/app.env as a symlink to an arbitrary reachable path and then send PUT /api/user-config/demoapp3:_user with attacker-controlled appEnv content. FilesystemService.writeTextFile() follows the planted link, allowing content to be written outside the intended restore and user-config directory boundary with Runtipi process permissions. This issue is fixed in version 4.10.1. | |
| Title | Runtipi: Authenticated arbitrary file write via backup restore symlink planting | |
| Weaknesses | CWE-59 CWE-61 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-21T20:31:38.124Z
Reserved: 2026-06-16T15:13:28.166Z
Link: CVE-2026-55168
No data.
Status : Received
Published: 2026-08-21T21:17:00.410
Modified: 2026-08-21T21:17:00.410
Link: CVE-2026-55168
No data.
OpenCVE Enrichment
Updated: 2026-08-21T22:30:17Z