Notifiarr Dockwatch是Notifiarr公司开源的一款带美观 WebUI 的开源 Docker 容器自动更新与通知管理工具。 Notifiarr Dockwatch 0.6.567版本及之前版本存在安全漏洞,该漏洞源于缺少exit()函数后的身份验证重定向以及未经清理的输入传递给shell_exec()函数,导致未经验证的OS命令注入,允许远程攻击者通过composePath POST参数执行任意命令,进而完全控制主机系统。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Dockwatch through 0.6.567 contains an unauthenticated command injection caused by missing exit() after authentication redirect in loader.php and unsanitized input in ajax/compose.php, letting remote attackers execute arbitrary shell commands, exploit requires seeding a session flag via incomplete auth check. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-58455.yaml | POC Details |
No comments yet