PT-2026-4303 · Runtipi · Runtipi

Kkc73

·

Publicado

2026-01-22

·

Atualizado

2026-02-26

·

CVE-2026-24129

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Runtipi versions 3.7.0 through 4.6.9
Description Runtipi is a Docker-based, personal homeserver orchestrator. Versions 3.7.0 and above allow an authenticated user to execute arbitrary system commands on the host server. This occurs because the BackupManager does not sanitize filenames of uploaded backups, leading to the persistence of user-uploaded files directly to the host filesystem using the original filename provided in the request. An attacker can stage a file containing shell metacharacters at a predictable path, which is then referenced during the restore process, allowing for command execution. The BackupManager is the component affected. The vulnerable operation involves the storage and restoration of backup files.
Recommendations Update to version 4.7.0 or later.

Exploit

Correção

RCE

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24129
GHSA-VRGF-RCJ5-6GV9

Produtos afetados

Runtipi