MEDIUM
Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container
Published Sep 2, 2026
4.9
MEDIUMCVSS 3.1
EPSS 0.56%
Description
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio Dashboard exposes POST /api/functions without authentication by default (NOP auth mode). The spec.handler field (e.g., mymodule:myfunction) is parsed by functionconfig.ParseHandler() which splits on : only — no path validation is applied to the module portion. This issue has been patched in version 1.16.5.
Affected products
-
Affected
- < 1.16.5
No data.
No data.
No Red Hat product state for this CVE.
github.com/nuclio/nuclio
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/nuclio/nuclio | 0 | not fixed |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-70215 Advisory
- https://github.com/advisories/GHSA-wpcj-rmv4-86qg Advisory
- https://github.com/nuclio/nuclio/commit/2a55d3a8bd4d49226cb4742020303f5bf2a0931d x_refsource_MISC
- https://github.com/nuclio/nuclio/pull/4143 x_refsource_MISC
- https://github.com/nuclio/nuclio/releases/tag/1.16.5 x_refsource_MISC
- https://github.com/nuclio/nuclio/security/advisories/GHSA-wpcj-rmv4-86qg exploitx_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-70215 | Advisory | |
| https://github.com/advisories/GHSA-wpcj-rmv4-86qg | Advisory | |
| https://github.com/nuclio/nuclio/commit/2a55d3a8bd4d49226cb4742020303f5bf2a0931d | x_refsource_MISC | |
| https://github.com/nuclio/nuclio/pull/4143 | x_refsource_MISC | |
| https://github.com/nuclio/nuclio/releases/tag/1.16.5 | x_refsource_MISC | |
| https://github.com/nuclio/nuclio/security/advisories/GHSA-wpcj-rmv4-86qg | exploitx_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 2, 2026
Updated Sep 2, 2026
Reserved Jun 8, 2026
Link CVE-2026-52832
CISA Vulnrichment
Updated Sep 2, 2026
Red Hat
No data
GitHub
Link GHSA-WPCJ-RMV4-86QG