Goploy is an open-source automation deployment system. Prior to version 1.18.0, a severe path traversal vulnerability exists in its backend API endpoints, specifically /deploy/fileDiff (File Compare), when handling file paths provided by the client. This issue has been patched in version 1.18.0.
Metrics
Affected Vendors & Products
References
History
Mon, 31 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zhenorzz
Zhenorzz goploy |
|
| Vendors & Products |
Zhenorzz
Zhenorzz goploy |
Mon, 31 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Goploy is an open-source automation deployment system. Prior to version 1.18.0, a severe path traversal vulnerability exists in its backend API endpoints, specifically /deploy/fileDiff (File Compare), when handling file paths provided by the client. This issue has been patched in version 1.18.0. | |
| Title | Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise | |
| Weaknesses | CWE-200 CWE-22 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-08-31T18:46:52.095Z
Updated: 2026-08-31T19:35:12.871Z
Reserved: 2026-06-09T18:13:07.263Z
Link: CVE-2026-53553
Updated: 2026-08-31T19:34:51.365Z
Status : Received
Published: 2026-08-31T19:16:51.030
Modified: 2026-08-31T20:17:05.567
Link: CVE-2026-53553
No data.