PT-2026-84823 · Nuclio · Nuclio
CVE-2026-79755
·
Published
2026-09-02
·
Updated
2026-09-02
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nuclio versions prior to 1.17.4
Description
In the local Docker platform of this serverless framework, the function namespace is interpolated without validation into a
docker ps --filter "label=nuclio.io/namespace=<value>" command executed via the host shell (/bin/sh -c). Since the default authentication is set to nop (unauthenticated), a remote attacker can inject arbitrary OS commands. These commands execute as root within the dashboard container, which has access to the Docker socket, potentially leading to a full host compromise.Recommendations
Update to version 1.17.4.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nuclio