Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-79754— Nuclio: Kaniko build tempDir command injection

Quick assessment

Affected
nuclio nuclio
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Nuclio 是一个用于实时事件和数据处理的“Serverless”框架。在版本 1.6.19 至 1.17.2 之前的版本中,Nuclio 仪表盘的构建流水线在将 字段用于构建 shell 命令前,未对其进行清洗(sanitization)。当启用 Kaniko 容器构建器时,拥有函数创建权限的用户可以向该字段注入 shell 元字符,从而在运行于 Kubernetes 服务账户(该账户在其命名空间内对 Secrets、Pods、Jobs 和 Deployments 具有通配符访问权限)的 Dashboard 容

CVSS 7.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-79754

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Nuclio: Kaniko build tempDir command injection
Source: CVE Program / CVE List V5
Vulnerability Description
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. From version 1.6.19 to before version 1.17.2, Nuclio's Dashboard build pipeline does not sanitize the spec.build.tempDir field before using it to construct a shell command. When the Kaniko container builder is enabled, a user with function-create permission can inject shell metacharacters into this field and achieve arbitrary command execution inside the Dashboard container, which runs with a Kubernetes service account holding wildcard access to Secrets, Pods, Jobs, and Deployments in its namespace. This issue has been patched in version 1.17.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
nuclio nuclio >= 1.6.19, < 1.17.2 -

II. Public POCs for CVE-2026-79754

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-79754

登录查看更多情报信息。

Other References for CVE-2026-79754 (4)

Same Patch Batch · nuclio · 2026-09-02 · 7 CVEs total

CVE-2026-79756 8.7 HIGH Nuclio: Unauthenticated OS command injection via namespace header in list-all resource pat
CVE-2026-45730 8.3 HIGH Nuclio: Missing authorization on project write paths allows any authenticated user to modi
CVE-2026-52833 8.0 HIGH Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads
CVE-2026-52831 8.0 HIGH Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command le
CVE-2026-79755 8.0 HIGH Nuclio: Unauthenticated OS command injection via function namespace in docker ps --filter
CVE-2026-52832 4.9 MEDIUM Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dash

IV. Related Vulnerabilities

V. Comments for CVE-2026-79754

No comments yet


Leave a comment