HIGH
Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE
Published Sep 2, 2026
8.0
HIGHCVSS 3.1
EPSS 0.55%
Description
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runtimeAttributes.repositories[] values with the {{ . }} action, which performs no escaping. An attacker can embed a closing brace (}) to break out of the repositories {} block and append arbitrary Groovy statements that execute unconditionally during the Gradle configuration phase. This issue has been patched in version 1.16.5.
Affected products
-
- Version < 1.16.5StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/nuclio/nuclio
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/nuclio/nuclio | 0 | not fixed |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-70216 Advisory
- https://github.com/advisories/GHSA-3v79-m2cg-89ww Advisory
- https://github.com/nuclio/nuclio/commit/4c78040c759068e927f3ed7c6507543c15d4ae56 x_refsource_MISC
- https://github.com/nuclio/nuclio/pull/4149 x_refsource_MISC
- https://github.com/nuclio/nuclio/releases/tag/1.16.5 x_refsource_MISC
- https://github.com/nuclio/nuclio/security/advisories/GHSA-3v79-m2cg-89ww exploitx_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-70216 | Advisory | |
| https://github.com/advisories/GHSA-3v79-m2cg-89ww | Advisory | |
| https://github.com/nuclio/nuclio/commit/4c78040c759068e927f3ed7c6507543c15d4ae56 | x_refsource_MISC | |
| https://github.com/nuclio/nuclio/pull/4149 | x_refsource_MISC | |
| https://github.com/nuclio/nuclio/releases/tag/1.16.5 | x_refsource_MISC | |
| https://github.com/nuclio/nuclio/security/advisories/GHSA-3v79-m2cg-89ww | exploitx_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 2, 2026
Updated Sep 2, 2026
Reserved Jun 8, 2026
Link CVE-2026-52833
CISA Vulnrichment
Updated Sep 2, 2026
ENISA EUVD
EUVD-2026-70216 GHSA-3V79-M2CG-89WW Assigner GitHub_M
Published Sep 2, 2026
Updated Sep 2, 2026
Exploited since n/a
Link EUVD-2026-70216