PT-2026-50119 · Runtipi · Runtipi

·

CVE-2026-47277

·

Published

2026-06-16

·

Updated

2026-06-17

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Runtipi versions 4.9.1 through 4.9.3
Description Runtipi serves marketplace app logos from files inside cloned app-store repositories through an unauthenticated endpoint. A path guard only checks the lexical path before Node reads the file, allowing a Git app store containing metadata/logo.jpg as a symbolic link to cause the system to read and return the symlink target. Since the endpoint is public and the target may point outside the cloned repository, this can expose local files from the Runtipi container, such as /data/.env, /data/state/seed, logs, or application files. This may lead to the disclosure of JWT (JSON Web Token) secrets, service credentials, local configuration, and operational logs.
Recommendations Update to version 4.10.0.

Exploit

Fix

Path traversal

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47277
GHSA-QRQJ-P7HM-4M66

Affected Products

Runtipi