CVE-2026-33344 PUBLISHED CVSS 8.100000381469727 HIGH

Dagu has an incomplete fix for CVE-2026-27598: path traversal via %2F-encoded slashes in locateDAG

EPSS 0.02% · 3.5th percentile

Risk Scores

CVSS v3.1
8.100000381469727
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.02%
3.5th percentile

Affected Products

VendorProductVersions
dagu-orgdagu>= 2.0.0, < 2.3.1, >= 2.0.0, < 2.3.1, >= 2.0.0, < 2.3.1
github.comdagu-org/dagu1.30.4-0.20260221021317-e2ed589105d7, 1.30.4-0.20260221021317-e2ed589105d7, 1.30.4-0.20260221021317-e2ed589105d7
dagudagu2.0.0, 2.0.0, 2.0.0

Timeline

References

Open in Interactive Console →