Server-Side Template Injection in Tugtainer by Quenary
CVE-2026-47752
9.9CRITICAL
What is CVE-2026-47752?
Tugtainer, a self-hosted application designed for automating Docker container updates, is affected by a Server-Side Template Injection (SSTI) vulnerability. This issue arises from the notification template rendering, which utilizes an unsandboxed jinja2.Environment. Consequently, any authenticated user can exploit this to execute arbitrary operating system commands with root privileges inside the affected Docker container. This vulnerability exists in versions prior to 1.30.2, which resolves the issue and enhances security.
Affected Version(s)
tugtainer < 1.30.2
