CVE-2026-25116 HIGH

CVE-2026-25116: Runtipi vulnerable to unauthenticated docker-compose.yml Overwrite via Path Traversal

Vendor Runtipi
Product runtipi
Weakness CWE-22 · Path traversal
Published January 29, 2026
Last update February 2, 2026

CVSS base score

7.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L

What the vulnerability does

01Description

Runtipi is a personal homeserver orchestrator. Starting in version 4.5.0 and prior to version 4.7.2, an unauthenticated Path Traversal vulnerability in the `UserConfigController` allows any remote user to overwrite the system's `docker-compose.yml` configuration file. By exploiting insecure URN parsing, an attacker can replace the primary stack configuration with a malicious one, resulting in full Remote Code Execution (RCE) and host filesystem compromise the next time the instance is restarted by the operator. Version 4.7.2 fixes the vulnerability.

Key dates

02Disclosure timeline

January 29, 2026 CVE published
February 2, 2026 Record updated