Path Traversal Vulnerability in Goploy Automation Deployment System
CVE-2026-53553
7.7HIGH
What is CVE-2026-53553?
Goploy, an open-source automation deployment system, has a vulnerability in its backend API endpoints, specifically within the /deploy/fileDiff function. This path traversal issue allows unauthorized file access due to improper validation of file paths provided by the client. The vulnerability has been addressed in version 1.18.0, which patches the flaw to prevent potential security breaches. Users are encouraged to update to this version to ensure their system's security.
Affected Version(s)
goploy < 1.18.0
