PT-2026-84823 · Nuclio · Nuclio

CVE-2026-79755

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nuclio versions prior to 1.17.4
Description In the local Docker platform of this serverless framework, the function namespace is interpolated without validation into a docker ps --filter "label=nuclio.io/namespace=<value>" command executed via the host shell (/bin/sh -c). Since the default authentication is set to nop (unauthenticated), a remote attacker can inject arbitrary OS commands. These commands execute as root within the dashboard container, which has access to the Docker socket, potentially leading to a full host compromise.
Recommendations Update to version 1.17.4.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79755
GHSA-2893-RQ73-W22X

Affected Products

Nuclio