The CVE-2026-79756 vulnerability affects Nuclio versions prior to 1.17.4, allowing for unauthenticated OS command injection in the Nuclio dashboard on the local/Docker platform. This vulnerability has a high CVSS score of 8.7 and is considered HIGH severity. The vulnerability was published on 2026-09-02T17:18:00.087Z and has not been modified since then. Users of Nuclio versions prior to 1.17.4 should tak [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T17:17:59.940Z and has not been modified since then. CVE-2026-79755 is a HIGH-severity vulnerability in Nuclio's local Docker platform. Unvalidated namespace input is interpolated into a docker ps command, allowing remote attackers to inject OS commands as root. This is possible due to the default [truncated]
The Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh, -c, <command>). Two fields in the trigger specification flow into this string without adequate sanitization: event.headers keys and event.body. This issue has been patched in version 1.16.4. Nuclio users, administrators of Nuclio deployments, and security teams [truncated]