PT-2026-79455 · Runtipi · Runtipi
CVE-2026-55168
·
Published
2026-08-21
·
Updated
2026-08-21
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Runtipi versions prior to 4.10.1
Description
Runtipi accepts symbolic links from an attacker-controlled backup archive and copies them into live application paths during the backup restore flow. An authenticated attacker can create a symlink at
user-config/app.env pointing to an arbitrary reachable path and then send a request to the endpoint "PUT /api/user-config/demoapp3: user" with controlled appEnv content. The function writeTextFile() in FilesystemService follows the planted link, enabling the writing of content outside the intended restore and user-config directory boundaries using Runtipi process permissions.Recommendations
Update to version 4.10.1.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Runtipi