CVE-2026-53552: CWE-639: Authorization Bypass Through User-Controlled Key in zhenorzz goploy
Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row id from the JSON body and act on it without checking that the project belongs to the caller's namespace. The corresponding model.ProjectFile.GetData and model.Project.GetData queries filter only by row id. A user holding the manager role (or any role that includes the FileSync / EditProject permission) in their own namespace can read, write, or delete files in any project across the install, and can rewrite any project's git remote URL by submitting the foreign id in the body. The git-URL primitive escalates to RCE on the next deploy because Edit runs git remote set-url on the project's working tree. At time of publication, there are no known publicly available patches.
AI Analysis
Technical Summary
In goploy versions 1.17.5 and prior, several API handlers (Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit) accept project or project-file row IDs from JSON input and perform actions without verifying that the project belongs to the caller's namespace. The underlying data queries filter only by row ID, not ownership. Consequently, a user with manager role or roles including FileSync/EditProject permissions can manipulate files or project settings across the entire installation. Specifically, the ability to rewrite the git remote URL escalates to remote code execution because the Edit handler runs 'git remote set-url' on the project's working tree during deployment. At the time of publication, no official patches or fixes are available.
Potential Impact
An attacker with manager-level permissions in their own namespace can bypass authorization controls to access and modify files in any project on the goploy installation. This includes reading, writing, and deleting files arbitrarily. Furthermore, the attacker can change the git remote URL of any project, which leads to remote code execution during the next deployment process. This vulnerability compromises confidentiality, integrity, and can lead to full system compromise. There are no known public exploits in the wild yet.
Mitigation Recommendations
At the time of this report, no official patches or fixes are available for this vulnerability. Users should monitor the vendor's advisories for updates. Until a fix is released, restrict manager and FileSync/EditProject permissions to trusted users only and consider limiting access to the deployment system to reduce risk.
CVE-2026-53552: CWE-639: Authorization Bypass Through User-Controlled Key in zhenorzz goploy
Description
Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row id from the JSON body and act on it without checking that the project belongs to the caller's namespace. The corresponding model.ProjectFile.GetData and model.Project.GetData queries filter only by row id. A user holding the manager role (or any role that includes the FileSync / EditProject permission) in their own namespace can read, write, or delete files in any project across the install, and can rewrite any project's git remote URL by submitting the foreign id in the body. The git-URL primitive escalates to RCE on the next deploy because Edit runs git remote set-url on the project's working tree. At time of publication, there are no known publicly available patches.
CVSS v3.1
Score 9.6critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In goploy versions 1.17.5 and prior, several API handlers (Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit) accept project or project-file row IDs from JSON input and perform actions without verifying that the project belongs to the caller's namespace. The underlying data queries filter only by row ID, not ownership. Consequently, a user with manager role or roles including FileSync/EditProject permissions can manipulate files or project settings across the entire installation. Specifically, the ability to rewrite the git remote URL escalates to remote code execution because the Edit handler runs 'git remote set-url' on the project's working tree during deployment. At the time of publication, no official patches or fixes are available.
Potential Impact
An attacker with manager-level permissions in their own namespace can bypass authorization controls to access and modify files in any project on the goploy installation. This includes reading, writing, and deleting files arbitrarily. Furthermore, the attacker can change the git remote URL of any project, which leads to remote code execution during the next deployment process. This vulnerability compromises confidentiality, integrity, and can lead to full system compromise. There are no known public exploits in the wild yet.
Mitigation Recommendations
At the time of this report, no official patches or fixes are available for this vulnerability. Users should monitor the vendor's advisories for updates. Until a fix is released, restrict manager and FileSync/EditProject permissions to trusted users only and consider limiting access to the deployment system to reduce risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-26rh-24rg-j3vv
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53552"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6a4e4ee7c9d9e3dbe3289b43
Added to database: 07/08/2026, 13:21:43 UTC
Last enriched: 09/07/2026, 11:07:10 UTC
Last updated: 09/13/2026, 23:59:00 UTC
Views: 85
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.