
Dagu patches API path traversal after incomplete prior fix
CVE-2026-33344 is a High-severity path traversal in Dagu’s web API letting low-privileged authenticated users traverse outside the DAGs directory via `%2F`-encoded slashes.
NewsWeb SecurityDevOps
1 min24 Mar 2026
