github.com/dagu-org/dagu
Go3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/dagu-org/dagupage 1 of 1
- CVE-2026-27598MEDIUMCVSS 6.5EG 6.52026-02-25
Dagu is a workflow engine with a built-in Web user interface. In versions up to and including 1.16.7, the `CreateNewDAG` API endpoint (`POST /api/v1/dags`) does not validate the DAG name before passing it to the file store. An authenticate…
- CVE-2026-31886CRITICALCVSS 7.6EG 9.12026-03-13
Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the inline DAG execution endpoints is passed directly into filepath.Join to construct a temporary directory path without a…
- CVE-2026-33344HIGHCVSS 8.1EG 8.1✓ Fixed in 1.30.4-0.20260319093346-7d07fda8f9de2026-03-24
Dagu is a workflow engine with a built-in Web user interface. From version 2.0.0 to before version 2.3.1, the fix for CVE-2026-27598 added ValidateDAGName to CreateNewDAG and rewrote generateFilePath to use filepath.Base. This patched the …
Check whether github.com/dagu-org/dagu is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/dagu-org/dagu CVEs against the assets you own.
Start Free Scan →