PT-2026-50119 · Runtipi · Runtipi
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Runtipi versions 4.9.1 through 4.9.3
Description
Runtipi serves marketplace app logos from files inside cloned app-store repositories through an unauthenticated endpoint. A path guard only checks the lexical path before Node reads the file, allowing a Git app store containing
metadata/logo.jpg as a symbolic link to cause the system to read and return the symlink target. Since the endpoint is public and the target may point outside the cloned repository, this can expose local files from the Runtipi container, such as /data/.env, /data/state/seed, logs, or application files. This may lead to the disclosure of JWT (JSON Web Token) secrets, service credentials, local configuration, and operational logs.Recommendations
Update to version 4.10.0.
Exploit
Fix
Path traversal
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Runtipi