---
id: CVE-2026-55168
title: Runtipi is a personal homeserver orchestrator
summary: >-
  Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi
  accepts symbolic links from an attacker-controlled backup archive and copies
  them into live application paths during the backup restore flow. An
  authenticated …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-59
  - CWE-61
published: '2026-08-21'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T19:57:08.043'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55168'
references:
  - url: >-
      https://github.com/runtipi/runtipi/commit/df529a211b05f3a0007b209b6c337f8c1942619c
    label: security-advisories@github.com
  - url: 'https://github.com/runtipi/runtipi/pull/2606'
    label: security-advisories@github.com
  - url: 'https://github.com/runtipi/runtipi/releases/tag/v4.10.1'
    label: security-advisories@github.com
  - url: 'https://github.com/runtipi/runtipi/security/advisories/GHSA-wcrf-g9p9-2wg7'
    label: security-advisories@github.com
  - url: 'https://github.com/runtipi/runtipi/security/advisories/GHSA-wcrf-g9p9-2wg7'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - exploit-available
epss: 0.00609
epssPercentile: 0.47147
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/KovachVL/CVE-2026-55168'
  checkedAt: '2026-09-30T20:23:53.987Z'
exploitAvailable: true
ingestedAt: '2026-09-30T20:23:19.469Z'
---

## Overview

Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-controlled backup archive and copies them into live application paths during the backup restore flow. An authenticated attacker can plant user-config/app.env as a symlink to an arbitrary reachable path and then send PUT /api/user-config/demoapp3:_user with attacker-controlled appEnv content. FilesystemService.writeTextFile() follows the planted link, allowing content to be written outside the intended restore and user-config directory boundary with Runtipi process permissions. This issue is fixed in version 4.10.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
