Runtipi is a modestly represented self-hosting platform that enables users to deploy and manage applications on personal infrastructure, with its vulnerability footprint concentrated in authentication and access-control weaknesses including missing authentication for critical functions, improper rate limiting, path traversal, OS command injection, and excessive authentication-attempt tolerance. These classes reflect the inherent risks of a user-facing, application-aggregation system where input validation and access boundaries are central to isolating tenant workloads and preventing lateral movement. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Runtipi over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32729HIGH Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting, or account lockout m | Mar 13, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-31881CRITICAL Runtipi is a personal homeserver orchestrator. Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin) password when a password-reset request is active, resultin | Mar 11, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-24129HIGH Runtipi is a Docker-based, personal homeserver orchestrator that facilitates multiple services on a single server. Versions 3.7.0 and above allow an authenticated user to execute a | Jan 22, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-25116HIGH Runtipi is a personal homeserver orchestrator. Starting in version 4.5.0 and prior to version 4.7.2, an unauthenticated Path Traversal vulnerability in the `UserConfigController` a | Jan 29, 2026 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Runtipi.
Media articles that mention a CVE ID that affects a product developed by Runtipi — matched by CVE ID, not by vendor name.