
SecAlerts@SecAlertsCo
Patch
⚙️ CVE-2026-52831: Critical (CVSS 10) OS command injection in Nuclio. Unsanitized cron trigger fields get embedded into a curl invocation string passed to /bin/sh -c in Kubernetes CronJobs. No auth needed. Update to v1.16.4. https://secalerts.co/vulnerability/CVE-2026-52831?utm_campaign=x https://t.co/RNuxaOciL8
Post summary
CVE‑2026‑52831 is a critical OS command injection flaw in Nuclio that allows unauthenticated command execution via unsanitized cron trigger fields; a patch is available in version 1.16.4, and no active exploitation has been reported.
0000099
852 followersView on X
