Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.0
CVE-2026-52831: Nuclio before 1.16.4 can run crafted commands
CVE-2026-52831 · published 25 days ago
Summary
Versions of Nuclio earlier than 1.16.4 build a command line for scheduled tasks using data that isn’t properly cleaned. An attacker who can influence that data could cause the system to run unintended commands. Upgrade to version 1.16.4 or later to fix the issue.
What to do
- Update github.com nuclio to version 0.0.0-20260601075854-3356b86a8bfa.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | nuclio | nuclio | < 1.16.4 |
| go | github.com | nuclio |
< 0.0.0-20260601075854-3356b86a8bfa Fix: upgrade to 0.0.0-20260601075854-3356b86a8bfa
|
Original advisory text
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as th...
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh, -c, <command>). Two fields in the trigger specification flow into this string without adequate sanitization: event.headers keys and event.body. This issue has been patched in version 1.16.4.
Severity
8.0
High
CVSS 3.1: 10.0 (GHSA)
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
Timeline
Published2 Sep 2026
Updated27 Sep 2026
First seen8 Jul 2026
Track software like this
Free during beta