Executive brief
Nuclio, an open-source serverless platform, contains a vulnerability in its Dashboard component that allows unauthenticated users to write files to any location within the Dashboard's container. Because the Dashboard process runs with administrative (root) privileges, an attacker could overwrite critical system files or configuration settings. This could lead to a complete takeover of the container and potentially allow the attacker to gain broader access to the underlying Kubernetes cluster.
Technical details
A path traversal vulnerability exists in the Nuclio Dashboard's 'POST /api/functions' endpoint. The 'spec.handler' field is parsed by 'functionconfig.ParseHandler()' without path validation. During the build process, 'writeFunctionSourceCodeToTempFile()' uses 'path.Join' with the attacker-supplied module name, which resolves '../' sequences and allows the resulting path to escape the intended temporary directory. The Dashboard process, running as root, then writes attacker-controlled content to this path using 'os.WriteFile'. This allows for arbitrary file writes within the container filesystem, including sensitive directories like /etc or /usr/local/bin. An attacker can leverage this to achieve code execution or escalate privileges within the Kubernetes namespace using the Dashboard's service account token.
Affected products
- Nuclio Nuclio <= 1.15.27
Timeline
- 2026-05-17: disclosed: Vulnerability verified by researcher
- 2026-06-05: advisory: GitHub Advisory published
- 2026-07-16: advisory: CVE-2026-52832 published
- 1.16.5: patched