Dagu is a workflow automation and task scheduling tool that, despite a narrow product footprint, achieves notable prominence in its application domain through its durable signal centered on path-traversal and authentication-bypass vulnerabilities. These weakness classes reflect the tool's file-system access and command-execution capabilities, areas where improper input validation and access controls create direct risk to users operating the platform in networked environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dagu over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31886HIGH Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the inline DAG execution endpoints is passed directly into file | Mar 13, 2026 | 7.6 | 28 | NO | NO |
CVE-2026-33344HIGH Dagu is a workflow engine with a built-in Web user interface. From version 2.0.0 to before version 2.3.1, the fix for CVE-2026-27598 added ValidateDAGName to CreateNewDAG and rewro | Mar 24, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-31882HIGH Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, when Dagu is configured with HTTP Basic authentication (DAGU_AUTH_MODE=basic), all Server-Sent Events | Mar 13, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-27598MEDIUM Dagu is a workflow engine with a built-in Web user interface. In versions up to and including 1.16.7, the `CreateNewDAG` API endpoint (`POST /api/v1/dags`) does not validate the DA | Feb 25, 2026 | 6.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dagu.
Media articles that mention a CVE ID that affects a product developed by Dagu — matched by CVE ID, not by vendor name.