CRITICAL
DataLinkDC
CVE published 2026-08-06
CVE-2026-70558
The Dinky application has a critical vulnerability in its POST /download/uploadFromRsByLocal handler, allowing arbitrary file writes with a hardcoded token. This affects Dinky v1.2.5 and the development branch. The default Docker image runs on port 8888 with no proxy or authentication and chmod 777 on /opt/dinky, making the application's classpath, launch scripts, and static assets writable. Writes are ma [truncated]