CVE-2026-31886 is a path traversal vulnerability (CWE-22) affecting Dagu workflow engine versions prior to 2.2.4. An authenticated attacker can exploit this by manipulating the dagRunId field, causing the deletion of arbitrary files or directories, including the system's /tmp directory on root or Docker deployments. This results in a high-severity Denial of Service (DoS) with a CVSS score of 7.6, capable of disrupting system operations. Despite being on the Hot List and having some community discussion, there is currently no public exploit code available and no evidence of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.4CPE matchmatch criteria | cpe:2.3:a:dagu:dagu:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.