Back

MEDIUM

Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container

Published Sep 2, 2026

Description

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio Dashboard exposes POST /api/functions without authentication by default (NOP auth mode). The spec.handler field (e.g., mymodule:myfunction) is parsed by functionconfig.ParseHandler() which splits on : only — no path validation is applied to the module portion. This issue has been patched in version 1.16.5.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Sep 2, 2026
Updated Sep 2, 2026
Reserved Jun 8, 2026

CISA Vulnrichment

Updated Sep 2, 2026

NVD

Status Deferred
Modified Sep 9, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Sep 2, 2026
Updated Sep 2, 2026