High severity7.6OSV Advisory· Published Jan 29, 2026· Updated Jun 17, 2026
CVE-2026-25116
CVE-2026-25116
Description
Runtipi is a personal homeserver orchestrator. Starting in version 4.5.0 and prior to version 4.7.2, an unauthenticated Path Traversal vulnerability in the UserConfigController allows any remote user to overwrite the system's docker-compose.yml configuration file. By exploiting insecure URN parsing, an attacker can replace the primary stack configuration with a malicious one, resulting in full Remote Code Execution (RCE) and host filesystem compromise the next time the instance is restarted by the operator. Version 4.7.2 fixes the vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/runtipi/runtipi/security/advisories/GHSA-mwg8-x997-cqw6nvdExploitVendor Advisory
- github.com/runtipi/runtipi/releases/tag/v4.7.2nvdProductRelease Notes
News mentions
0No linked articles in our index yet.