Security: dagucloud/dagu
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Incomplete fix for CVE-2026-27598: path traversal via %2F-encoded slashes in locateDAGGHSA-ph8x-4jfv-v9v8 published
Mar 19, 2026 by yottahmdHigh -
SSE Authentication Bypass in Basic Auth ModeGHSA-9wmw-9wph-2vwp published
Mar 13, 2026 by yottahmdHigh -
Path Traversal via `dagRunId` in Inline DAG ExecutionGHSA-m4q3-457p-hh2x published
Mar 13, 2026 by yottahmdCritical -
Unauthenticated RCE via inline DAG spec in default configurationGHSA-6qr9-g2xw-cw92 published
Feb 19, 2026 by yottahmdLow -
Path traversal in DAG creation allows arbitrary YAML file write outside DAGs directoryGHSA-6v48-fcq6-ff23 published
Feb 21, 2026 by yottahmdLow
Learn more about advisories related to dagucloud/dagu in the GitHub Advisory Database