<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:dockhand:dockhand:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3adockhanddockhand/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 20:29:41 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3adockhanddockhand/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-53988 - Dockhand Authentication Bypass and Arbitrary Redeployment</title><link>https://feed.craftedsignal.io/briefs/2026-09-dockhand-auth-bypass/</link><pubDate>Tue, 29 Sep 2026 20:29:41 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-dockhand-auth-bypass/</guid><description>Dockhand versions prior to 1.0.40 contain an authentication bypass in git webhook endpoints allowing unauthenticated attackers to force arbitrary stack redeployments, leading to denial of service or potential host compromise.</description><content:encoded><![CDATA[<p>Dockhand versions before 1.0.40 are affected by an authentication bypass vulnerability (CVE-2026-53988) residing in its git webhook endpoints. The vulnerability stems from a flawed guard condition where a null webhook secret is incorrectly processed. This allows remote, unauthenticated attackers to send specially crafted, unsigned webhook requests to the application. By enumerating sequential stack IDs, an attacker can trigger unauthorized git clone and docker compose operations. If an attacker has write access to the git repository tracked by the stack, they can inject a malicious docker-compose.yml file containing privileged bind mounts, facilitating container escape and full host compromise. This flaw poses a critical risk to organizations relying on Dockhand for automated container orchestration, as it enables both service disruption and complete infrastructure takeover.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs reconnaissance to identify public-facing Dockhand instances.</li>
<li>Attacker enumerates sequential integer-based stack IDs associated with the target's git webhook endpoints.</li>
<li>Attacker constructs unsigned HTTP POST requests targeted at identified webhook endpoints.</li>
<li>Attacker exploits the null secret guard condition to bypass authentication checks.</li>
<li>Attacker triggers a forced 'git clone' and 'docker compose' deployment operation via the webhook.</li>
<li>Attacker modifies the tracked git repository to include a malicious docker-compose.yml file.</li>
<li>Attacker triggers the redeployment, causing the malicious compose file to be executed with host-level privileges via bind mounts.</li>
<li>Attacker achieves container escape and full host compromise.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to unauthorized infrastructure management. Attackers can trigger mass redeployments, causing denial of service. Furthermore, if the attacker can modify the repository linked to a stack, they can execute arbitrary code on the underlying host, resulting in container escape and total server compromise.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Dockhand to version 1.0.40 or later immediately to address CVE-2026-53988.</li>
<li>Restrict network access to Dockhand webhook endpoints, allowing only legitimate source IP ranges (such as those from GitLab or GitHub webhooks).</li>
<li>Implement monitor-only logging for all POST requests directed at /webhooks/git/* endpoints to identify attempts at sequential ID enumeration.</li>
<li>Audit all active git-tracked stacks in Dockhand to ensure that linked repositories are secured against unauthorized commit access.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>