← Back to overview

A severe path traversal vulnerability has been identified in Goploy, an open-source automation deployment system, affecting versions prior to 1.18.0. The vulnerability exists in the backend API endpoint /deploy/fileDiff (File Compare), which improperly handles file paths provided by clients. This flaw could allow attackers to traverse the file system and access arbitrary files outside the intended directory. The vulnerability has been classified as severe, indicating significant risk to affected deployments. A patch has been released in version 1.18.0 of Goploy. Users are strongly advised to upgrade to the patched version immediately. The fix is documented in a specific commit and detailed in a GitHub Security Advisory. No active exploitation has been mentioned, but the severity of path traversal vulnerabilities makes prompt remediation critical.

Affected products

  • Goploy

Related CVE's

  • CVE-2026-53553

Categories

  • Enterprise Applications
  • Web Technologies