CVE-2026-79754

Source
https://cve.org/CVERecord?id=CVE-2026-79754
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79754.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-79754
Aliases
  • GHSA-x44h-qmrv-mh72
Published
2026-09-02T16:38:50.441Z
Modified
2026-09-04T03:46:00.152788100Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Nuclio: Kaniko build tempDir command injection
Details

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. From version 1.6.19 to before version 1.17.2, Nuclio's Dashboard build pipeline does not sanitize the spec.build.tempDir field before using it to construct a shell command. When the Kaniko container builder is enabled, a user with function-create permission can inject shell metacharacters into this field and achieve arbitrary command execution inside the Dashboard container, which runs with a Kubernetes service account holding wildcard access to Secrets, Pods, Jobs, and Deployments in its namespace. This issue has been patched in version 1.17.2.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79754.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-77"
    ]
}
References

Affected packages

Git / github.com/nuclio/nuclio

Affected ranges

Type
GIT
Repo
https://github.com/nuclio/nuclio
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "1.6.19"
        },
        {
            "fixed": "1.17.2"
        }
    ]
}

Affected versions

1.*
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.11.0
1.11.1
1.11.10
1.11.11
1.11.12
1.11.13
1.11.14
1.11.15
1.11.16
1.11.17
1.11.18
1.11.19
1.11.2
1.11.20
1.11.21
1.11.22
1.11.23
1.11.24
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
1.11.9
1.12.0
1.12.1
1.12.10
1.12.11
1.12.12
1.12.13
1.12.14
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.12.9
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.14.0
1.14.1
1.14.2
1.14.3
1.14.5
1.14.6
1.14.7
1.14.8
1.15.1
1.15.10
1.15.11
1.15.12
1.15.13
1.15.14
1.15.15
1.15.16
1.15.17
1.15.18
1.15.19
1.15.2
1.15.20
1.15.21
1.15.22
1.15.23
1.15.24
1.15.25
1.15.3
1.15.8
1.15.9
1.16.0
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.17.0
1.17.1
1.6.19
1.6.20
1.6.21
1.6.22
1.6.23
1.6.24
1.6.25
1.6.26
1.6.27
1.6.28
1.6.29
1.6.30
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
2.*
2.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79754.json"