{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/dockhand--1.0.40/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:dockhand:dockhand:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-53988"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Dockhand (\u003c 1.0.40)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Dockhand"],"content_html":"\u003cp\u003eDockhand versions before 1.0.40 are affected by an authentication bypass vulnerability (CVE-2026-53988) residing in its git webhook endpoints. The vulnerability stems from a flawed guard condition where a null webhook secret is incorrectly processed. This allows remote, unauthenticated attackers to send specially crafted, unsigned webhook requests to the application. By enumerating sequential stack IDs, an attacker can trigger unauthorized git clone and docker compose operations. If an attacker has write access to the git repository tracked by the stack, they can inject a malicious docker-compose.yml file containing privileged bind mounts, facilitating container escape and full host compromise. This flaw poses a critical risk to organizations relying on Dockhand for automated container orchestration, as it enables both service disruption and complete infrastructure takeover.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify public-facing Dockhand instances.\u003c/li\u003e\n\u003cli\u003eAttacker enumerates sequential integer-based stack IDs associated with the target's git webhook endpoints.\u003c/li\u003e\n\u003cli\u003eAttacker constructs unsigned HTTP POST requests targeted at identified webhook endpoints.\u003c/li\u003e\n\u003cli\u003eAttacker exploits the null secret guard condition to bypass authentication checks.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a forced 'git clone' and 'docker compose' deployment operation via the webhook.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the tracked git repository to include a malicious docker-compose.yml file.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the redeployment, causing the malicious compose file to be executed with host-level privileges via bind mounts.\u003c/li\u003e\n\u003cli\u003eAttacker achieves container escape and full host compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to unauthorized infrastructure management. Attackers can trigger mass redeployments, causing denial of service. Furthermore, if the attacker can modify the repository linked to a stack, they can execute arbitrary code on the underlying host, resulting in container escape and total server compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Dockhand to version 1.0.40 or later immediately to address CVE-2026-53988.\u003c/li\u003e\n\u003cli\u003eRestrict network access to Dockhand webhook endpoints, allowing only legitimate source IP ranges (such as those from GitLab or GitHub webhooks).\u003c/li\u003e\n\u003cli\u003eImplement monitor-only logging for all POST requests directed at /webhooks/git/* endpoints to identify attempts at sequential ID enumeration.\u003c/li\u003e\n\u003cli\u003eAudit all active git-tracked stacks in Dockhand to ensure that linked repositories are secured against unauthorized commit access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T20:29:41Z","date_published":"2026-09-29T20:29:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-dockhand-auth-bypass/","summary":"Dockhand versions prior to 1.0.40 contain an authentication bypass in git webhook endpoints allowing unauthenticated attackers to force arbitrary stack redeployments, leading to denial of service or potential host compromise.","title":"CVE-2026-53988 - Dockhand Authentication Bypass and Arbitrary Redeployment","url":"https://feed.craftedsignal.io/briefs/2026-09-dockhand-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Dockhand (\u003c 1.0.40)","version":"https://jsonfeed.org/version/1.1"}