Junglewise Threat Intelligence

Daptin path traversal and Zip Slip in cloudstore file upload

Severity: critical · CVSS 10 · Published 2026-04-10

Technologies: github.com/daptin/daptin (Go). Vendors: Go.

Executive brief

Daptin, an open-source backend-as-a-service platform, contains a critical security flaw in its file upload functionality. An unauthenticated attacker can upload specially crafted files to overwrite sensitive system files or place malicious code on the server. This could lead to a complete system takeover, data loss, or permanent disruption of services.

Technical details

A path traversal and 'Zip Slip' vulnerability exists in Daptin's `cloudstore.file.upload` action within `server/actions/action_cloudstore_file_upload.go`. The application fails to validate user-supplied filenames before writing them to disk, allowing attackers to use '..' sequences to escape the intended upload directory. This can be exploited by unauthenticated remote attackers to perform arbitrary file writes. By overwriting critical system files or uploading executable scripts, an attacker can achieve remote code execution (RCE). The vulnerability is addressed in version 0.12.0 by implementing path cleaning and prefix validation.

Affected products

  • Daptin Daptin <= 0.11.3

Timeline

  • 2026-04-05: patched: Fix committed to repository
  • 2026-04-10: advisory: GitHub Advisory published

References

Related threats