๐Ÿ” CVE Alert

CVE-2026-53553

HIGH 7.7

Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

Goploy is an open-source automation deployment system. Prior to version 1.18.0, a severe path traversal vulnerability exists in its backend API endpoints, specifically /deploy/fileDiff (File Compare), when handling file paths provided by the client. This issue has been patched in version 1.18.0.

CWE CWE-22 CWE-200
Vendor zhenorzz
Product goploy
Published Aug 31, 2026
Last Updated Aug 31, 2026
Stay Ahead of the Next One

Get instant alerts for zhenorzz goploy

Be the first to know when new high vulnerabilities affecting zhenorzz goploy are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

zhenorzz / goploy
< 1.18.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/zhenorzz/goploy/security/advisories/GHSA-4g5x-hcwm-82jw github.com: https://github.com/zhenorzz/goploy/commit/d51aa15ebc0a474d9d71d6c453a0fe798dd5e007 github.com: http://github.com/zhenorzz/goploy/releases/tag/v1.18.0