PT-2026-50677 · Unknown · Woodpecker
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Woodpecker versions 3.0.0 through 3.14.0
Description
A flaw in the gRPC layer of the CI/CD engine allows an authenticated agent to impersonate any other agent on the same server. This occurs because the server verifies the JWT (JSON Web Token) but subsequently ignores the verified identity, accepting a forged
agent id value provided in the outgoing gRPC metadata instead.Recommendations
Update to version 3.14.1.
As a temporary workaround, disable organization agents by setting
WOODPECKER DISABLE USER AGENT REGISTRATION=true and delete existing agents.Exploit
Fix
IDOR
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Woodpecker