CVE-2026-33344 is a high-severity path traversal vulnerability (CVSS 8.1) affecting Dagu workflow engine versions 2.0.0 through 2.3.0. This flaw allows an authenticated attacker with low privileges to exploit unvalidated API endpoints (GET, DELETE, RENAME, EXECUTE) by using %2F-encoded forward slashes in the filename parameter. This enables traversal outside the intended DAGs directory, leading to high confidentiality and integrity impacts, such as reading or modifying arbitrary files. There is currently no evidence of active exploitation, nor are public exploit codes available, and community attention is minimal. The vulnerability has been patched in Dagu version 2.3.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.3.1CPE matchmatch criteria | cpe:2.3:a:dagu:dagu:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.