{"id":"CVE-2026-55168","title":"Runtipi is a personal homeserver orchestrator","summary":"Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-controlled backup archive and copies them into live application paths during the backup restore flow. An authenticated …","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-59","CWE-61"],"published":"2026-08-21","updated":"2026-09-30","sourceUpdated":"2026-09-30T19:57:08.043","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55168","references":[{"url":"https://github.com/runtipi/runtipi/commit/df529a211b05f3a0007b209b6c337f8c1942619c","label":"security-advisories@github.com"},{"url":"https://github.com/runtipi/runtipi/pull/2606","label":"security-advisories@github.com"},{"url":"https://github.com/runtipi/runtipi/releases/tag/v4.10.1","label":"security-advisories@github.com"},{"url":"https://github.com/runtipi/runtipi/security/advisories/GHSA-wcrf-g9p9-2wg7","label":"security-advisories@github.com"},{"url":"https://github.com/runtipi/runtipi/security/advisories/GHSA-wcrf-g9p9-2wg7","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available"],"epss":0.00609,"epssPercentile":0.47147,"exploits":{"github":1,"githubRepos":["https://github.com/KovachVL/CVE-2026-55168"],"checkedAt":"2026-09-30T20:23:53.987Z"},"exploitAvailable":true,"ingestedAt":"2026-09-30T20:23:19.469Z","slug":"CVE-2026-55168","body":"## Overview\n\nRuntipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-controlled backup archive and copies them into live application paths during the backup restore flow. An authenticated attacker can plant user-config/app.env as a symlink to an arbitrary reachable path and then send PUT /api/user-config/demoapp3:_user with attacker-controlled appEnv content. FilesystemService.writeTextFile() follows the planted link, allowing content to be written outside the intended restore and user-config directory boundary with Runtipi process permissions. This issue is fixed in version 4.10.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}