PT-2026-102897 · Dockhand · Dockhand

·

CVE-2026-53988

·

Published

2026-09-29

·

Updated

2026-10-02

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dockhand versions prior to 1.0.40
Description An authentication bypass exists in the git webhook endpoints due to a null webhook secret guard condition. This allows unauthenticated remote attackers to trigger arbitrary stack redeployments by enumerating sequential stack IDs and sending unsigned webhook requests to force git clone and docker compose operations. This can lead to a denial of service or, if the attacker has write access to the tracked git branch, result in container escape and full host compromise through a malicious docker-compose.yml file utilizing privileged bind mounts.
Recommendations Update to version 1.0.40.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53988

Affected Products

Dockhand