VYPR
High severity7.6OSV Advisory· Published Jan 29, 2026· Updated Jun 17, 2026

CVE-2026-25116

CVE-2026-25116

Description

Runtipi is a personal homeserver orchestrator. Starting in version 4.5.0 and prior to version 4.7.2, an unauthenticated Path Traversal vulnerability in the UserConfigController allows any remote user to overwrite the system's docker-compose.yml configuration file. By exploiting insecure URN parsing, an attacker can replace the primary stack configuration with a malicious one, resulting in full Remote Code Execution (RCE) and host filesystem compromise the next time the instance is restarted by the operator. Version 4.7.2 fixes the vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Runtipi/RuntipiOSV3 versions
    e2e, nightly, v4.5.0, …+ 2 more
    • (no CPE)range: e2e, nightly, v4.5.0, …
    • cpe:2.3:a:runtipi:runtipi:*:*:*:*:*:*:*:*range: >=4.5.0,<4.7.2
    • (no CPE)range: 4.5.0 <= version < 4.7.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.