CVE-2026-25116 | Runtipi up to 4.7.1 URN Parser UserConfigController path traversal (GHSA-mwg8-x997-cqw6 / EUVD-2026-4942)
A vulnerability described as critical has been identified in Runtipi up to 4.7.1. This impacts the function UserConfigController of the component URN Parser. Such manipulation leads to path traversal.
This vulnerability is listed as CVE-2026-25116. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.