Pending AI Enrichment

This vulnerability was recently detected via the live feed and has not yet been processed by Precogs AI's context enrichment engine. The data below represents raw telemetric data.

RAW NVD TELEMETRY

CVE-2026-79755

CVSS Base Score
8.0 HIGH
Primary Weakness
CWE-78
Published Date
Sep 2, 2026
Data Source
NVD API

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is interpolated—unvalidated—into a double-quoted docker ps --filter "label=nuclio.io/namespace=<value>" command that is executed via the host shell (/bin/sh -c). Because the default auth kind is nop (unauthenticated), a remote attacker can inject arbitrary OS commands that run as root inside the dashboard container, which holds the Docker socket → host compromise. This issue has been patched in version 1.17.4.

Related Vulnerabilitiesvia CWE-78

Is your system affected?

Precogs AI detects CVE-2026-79755 in compiled binaries, LLMs, and application layers — even without source code access.