Command Injection Vulnerability in Nuclio Shell Runtime Affects Serverless Framework
CVE-2026-29042
8.9HIGH
What is CVE-2026-29042?
The Nuclio Shell Runtime, part of the Nuclio serverless framework, contains a command injection vulnerability prior to version 1.15.20. This vulnerability allows an attacker to exploit the system by sending crafted HTTP requests that manipulate the X-Nuclio-Arguments header. The runtime processes these user inputs insecurely, directly embedding them into shell commands without adequate validation or sanitization, potentially enabling unauthorized command execution. Version 1.15.20 includes a patch that resolves this issue.
Affected Version(s)
nuclio < 1.15.20
