Vulnerability Report: GO-2026-4785
- CVE-2026-33344, GHSA-ph8x-4jfv-v9v8
- Affects: github.com/dagu-org/dagu
- Published: Mar 23, 2026
- Unreviewed
Dagu has an incomplete fix for CVE-2026-27598: path traversal via %2F-encoded slashes in locateDAG in github.com/dagu-org/dagu
For detailed information about this vulnerability, visit https://github.com/dagu-org/dagu/security/advisories/GHSA-ph8x-4jfv-v9v8.
Affected Modules
-
PathGo Versions
-
from v1.30.4-0.20260221021317-e2ed589105d7 before v1.30.4-0.20260319093346-7d07fda8f9de
Aliases
References
- https://github.com/dagu-org/dagu/security/advisories/GHSA-ph8x-4jfv-v9v8
- https://github.com/dagu-org/dagu/commit/7d07fda8f9de3ae73dfb081ccd0639f8059c56bb
- https://vuln.go.dev/ID/GO-2026-4785.json
Feedback
This report is unreviewed. It was automatically generated from a third-party source and its details have not been verified by the Go team.
See anything missing or incorrect?
Suggest an edit to this report.