PatchSiren

DataLinkDC CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL DataLinkDC CVE published 2026-08-06

CVE-2026-70558

The Dinky application has a critical vulnerability in its POST /download/uploadFromRsByLocal handler, allowing arbitrary file writes with a hardcoded token. This affects Dinky v1.2.5 and the development branch. The default Docker image runs on port 8888 with no proxy or authentication and chmod 777 on /opt/dinky, making the application's classpath, launch scripts, and static assets writable. Writes are ma [truncated]