Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-46618— Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables

Quick assessment

Affected
fission fission
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Fission是Fission开源的一个基于Kubernetes的函数部署框架。 Fission 1.23.0之前版本存在操作系统命令注入漏洞,该漏洞源于构建器将Environment.spec.builder.command直接传递给exec.Command,未验证可执行路径或参数,允许用户创建或更新Environment CRD时在构建器Pod上下文中执行任意代码。

AI Predicted 7.8 Difficulty: Easy EPSS 0.60% · P47

Possible ATT&CK Techniques 1 AI

T1610 · Deploy Container

Affected Version Matrix 1

VendorProduct Version RangeStatus
fission fission < 1.23.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-46618

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables
Source: CVE Program / CVE List V5
Vulnerability Description
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, before the round-1 security sweep, pkg/builder/builder.go passed Environment.spec.builder.command directly into exec.Command(...) after a strings.Fields split, with no validation of the executable path or its arguments. A user who could create or update Environment CRDs in a namespace observed by the buildermgr could thereby point the builder pod at any executable inside the builder image (e.g. /bin/sh -c '...') and execute arbitrary code in the builder pod context. This issue has been patched in version 1.23.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5
Vulnerability Title
Fission 操作系统命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Fission是Fission开源的一个基于Kubernetes的函数部署框架。 Fission 1.23.0之前版本存在操作系统命令注入漏洞,该漏洞源于构建器将Environment.spec.builder.command直接传递给exec.Command,未验证可执行路径或参数,允许用户创建或更新Environment CRD时在构建器Pod上下文中执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
fission fission < 1.23.0 -

II. Public POCs for CVE-2026-46618

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-46618

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-46618 (1)

Vendor Advisories for CVE-2026-46618 (1)

Vendor Pages for CVE-2026-46618 (1)

Same Patch Batch · fission · 2026-06-10 · 17 CVEs total

CVE-2026-50563 9.9 CRITICAL Fission Container Executor Function PodSpec Injection Leading to Node Escape
CVE-2026-50566 9.9 CRITICAL Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows
CVE-2026-50545 9.9 CRITICAL Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover
CVE-2026-50564 9.9 CRITICAL Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, n
CVE-2026-46614 9.8 CRITICAL Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invo
CVE-2026-46612 8.8 HIGH Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function arc
CVE-2026-49824 8.5 HIGH Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function
CVE-2026-50570 8.5 HIGH Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows
CVE-2026-49823 7.7 HIGH Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission web
CVE-2026-49822 7.7 HIGH Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant
CVE-2026-49821 7.7 HIGH Fission: Cross-namespace Environment reference in Package allows build-time command execut
CVE-2026-50567 7.7 HIGH Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destin
CVE-2026-50565 4.9 MEDIUM Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-suppl
CVE-2026-50569 4.3 MEDIUM Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypass
CVE-2026-50568 3.6 LOW Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
CVE-2026-46617 Fission runtime pods automount the fission-fetcher service-account token into the user fun

IV. Related Vulnerabilities

V. Comments for CVE-2026-46618

No comments yet


Leave a comment