CVE-2026-52831High· 8.0▾ TwilightNuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
8 → 10
high → critical
10 → 8
critical → high
8 → 10
high → critical
10 → 8
critical → high
8 → 10
high → critical
10 → 8
critical → high
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh, -c, <command>). Two fields in the trigger specification flow into this string without adequate sanitization: event.headers keys and event.body. This issue has been patched in version 1.16.4.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/nuclio/nuclio < 0.0.0-20260601075854-3356b86a8bfaPatched in:
github.com/nuclio/nuclio 0.0.0-20260601075854-3356b86a8bfaField changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-52833High· 8.0Nuclio is a "Serverless" framework for Real-Time Events and Data Processing
CVE-2026-52832Medium· 4.9Nuclio is a "Serverless" framework for Real-Time Events and Data Processing
CVE-2018-11138Critical· 9.8The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
CVE-2020-3167High· 7.8A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS)
CVE-2019-1709Medium· 6.0A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack
CVE-2024-51378Critical· 10.0getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…