—
GO-2026-4785
Dagu has an incomplete fix for CVE-2026-27598: path traversal via %2F-encoded slashes in locateDAG in github.com/dagu-org/dagu
Quick fix
GO-2026-4785 — github.com/dagu-org/dagu: upgrade to the fixed version with the command below.
go get github.com/dagu-org/dagu@v1.30.4-0.20260319093346-7d07fda8f9deDetails
Dagu has an incomplete fix for CVE-2026-27598: path traversal via %2F-encoded slashes in locateDAG in github.com/dagu-org/dagu
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/dagu-org/dagu
Introduced in:
1.30.4-0.20260221021317-e2ed589105d7Fixed in: 1.30.4-0.20260319093346-7d07fda8f9deFix
go get github.com/dagu-org/dagu@v1.30.4-0.20260319093346-7d07fda8f9de