PT-2026-21750 · Bleon Ethical · Api-Gateway-Deploy

Bleon-Ethical

·

Publicado

2026-02-24

·

Atualizado

2026-03-01

·

CVE-2026-27208

CVSS v3.1

9.2

Crítica

VetorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions bleon-ethical/api-gateway-deploy version 1.0.0
Description The software is susceptible to an attack chain involving OS Command Injection and Privilege Escalation. Successful exploitation allows an attacker to execute arbitrary commands with root privileges within the container, potentially leading to a container escape and unauthorized infrastructure modifications. The issue is related to insufficient input validation and insecure configurations.
Recommendations Update to version 1.0.1, which includes fixes such as strict input sanitization and secure delimiters in the entrypoint.sh file, enforcement of a non-root user (appuser) in the Dockerfile, and mandatory security quality gates.

Exploit

Correção

LPE

Argument Injection

OS Command Injection

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27208
GHSA-CHH5-W73Q-4GMM

Produtos afetados

Api-Gateway-Deploy