PT-2026-21750 · Bleon Ethical · Api-Gateway-Deploy

Bleon-Ethical

·

Published

2026-02-24

·

Updated

2026-03-01

·

CVE-2026-27208

CVSS v3.1

9.2

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions bleon-ethical/api-gateway-deploy version 1.0.0
Description The software is susceptible to an attack chain involving OS Command Injection and Privilege Escalation. Successful exploitation allows an attacker to execute arbitrary commands with root privileges within the container, potentially leading to a container escape and unauthorized infrastructure modifications. The issue is related to insufficient input validation and insecure configurations.
Recommendations Update to version 1.0.1, which includes fixes such as strict input sanitization and secure delimiters in the entrypoint.sh file, enforcement of a non-root user (appuser) in the Dockerfile, and mandatory security quality gates.

Exploit

Fix

LPE

Argument Injection

OS Command Injection

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27208
GHSA-CHH5-W73Q-4GMM

Affected Products

Api-Gateway-Deploy