8.7 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
OpenWrt luci-app-dockerman Read ACL Remote Code Execution
OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the docker.container.ttyd_start method even though it performs mutating operations. The run_ttyd handler builds a shell command from the request-controlled id, cmd, and uid fields and passes it to system() without quoting or argv-style execution in the rpcd root context. An authenticated attacker holding only the luci-app-dockerman read ACL can inject shell metacharacters (e.g., in id) to execute arbitrary commands as root via an HTTP POST to /ubus. openwrt-24.10 and openwrt-23.05 do not contain this backend and are not affected; no patched version was known as of the advisory.
References
-
GitHub Security Advisory (GHSA-cq4h-h8jr-3xqv) vendor-advisory
-
VulnCheck Advisory: OpenWrt luci-app-dockerman Read ACL Remote Code Execution third-party-advisory
Affected products
- ==26.162.29621~507ab5e
Matching in nixpkgs
pkgs.lucide
Open-source icon library that provides 1000+ icons
pkgs.lucida-downloader
Multithreaded client for downloading music for free with lucida
pkgs.typstPackages.lucide
None
pkgs.haskellPackages.lucid
Clear to write, read and edit DSL for HTML
-
nixos-unstable 2.11.20250303
- nixpkgs-unstable 2.11.20250303
- nixos-unstable-small 2.11.20250303
-
nixos-26.05 2.11.20250303
- nixos-26.05-small 2.11.20250303
- nixpkgs-26.05-darwin 2.11.20250303
pkgs.haskellPackages.lucid2
Clear to write, read and edit DSL for HTML
-
nixos-unstable 0.0.20250303
- nixpkgs-unstable 0.0.20250303
- nixos-unstable-small 0.0.20250303
-
nixos-26.05 0.0.20250303
- nixos-26.05-small 0.0.20250303
- nixpkgs-26.05-darwin 0.0.20250303
pkgs.haskellPackages.lucid-cdn
Curated list of CDN imports for lucid
pkgs.haskellPackages.lucid-svg
DSL for SVG using lucid for HTML
pkgs.haskellPackages.htmx-lucid
Use htmx with lucid
pkgs.haskellPackages.lucid-htmx
Use htmx in your lucid templates
pkgs.typstPackages.lucide_0_1_0
None
pkgs.fontbhlucidatypewriter75dpi
Lucida Sans Typewriter 75dpi pcf fonts
-
nixos-unstable 75dpi-1.0.4
- nixpkgs-unstable 75dpi-1.0.4
- nixos-unstable-small 75dpi-1.0.4
-
nixos-26.05 75dpi-1.0.4
- nixos-26.05-small 75dpi-1.0.4
- nixpkgs-26.05-darwin 75dpi-1.0.4
pkgs.haskellPackages.Spock-lucid
Lucid support for Spock
pkgs.haskellPackages.cmark-lucid
Use cmark with Lucid
pkgs.fontbhlucidatypewriter100dpi
Lucida Sans Typewriter 100dpi pcf fonts
-
nixos-unstable 100dpi-1.0.4
- nixpkgs-unstable 100dpi-1.0.4
- nixos-unstable-small 100dpi-1.0.4
-
nixos-26.05 100dpi-1.0.4
- nixos-26.05-small 100dpi-1.0.4
- nixpkgs-26.05-darwin 100dpi-1.0.4
pkgs.haskellPackages.lucid-extras
Generate more HTML with Lucid - Bootstrap, Rdash, Vega-Lite, Leaflet JS, Email
pkgs.haskellPackages.lucid-xstatic
Lucid helper for XStatic
pkgs.haskellPackages.servant-lucid
Servant support for lucid
pkgs.font-bh-lucidatypewriter-75dpi
Lucida Sans Typewriter 75dpi pcf fonts
-
nixos-unstable 75dpi-1.0.4
- nixpkgs-unstable 75dpi-1.0.4
- nixos-unstable-small 75dpi-1.0.4
-
nixos-26.05 75dpi-1.0.4
- nixos-26.05-small 75dpi-1.0.4
- nixpkgs-26.05-darwin 75dpi-1.0.4
pkgs.haskellPackages.lucid2-xstatic
Lucid2 helper for XStatic
pkgs.font-bh-lucidatypewriter-100dpi
Lucida Sans Typewriter 100dpi pcf fonts
-
nixos-unstable 100dpi-1.0.4
- nixpkgs-unstable 100dpi-1.0.4
- nixos-unstable-small 100dpi-1.0.4
-
nixos-26.05 100dpi-1.0.4
- nixos-26.05-small 100dpi-1.0.4
- nixpkgs-26.05-darwin 100dpi-1.0.4
pkgs.haskellPackages.cheapskate-lucid
Use cheapskate with Lucid
pkgs.haskellPackages.lucid-foundation
Basic Zurb Foundation API in Lucid
pkgs.haskellPackages.skylighting-lucid
Lucid support for Skylighting
pkgs.python313Packages.openwrt-luci-rpc
Python module for interacting with the OpenWrt Luci RPC interface
pkgs.python314Packages.openwrt-luci-rpc
Python module for interacting with the OpenWrt Luci RPC interface
pkgs.haskellPackages.dani-servant-lucid2
Servant support for lucid2
Package maintainers
-
@jelni jel <nixpkgs@jel.gay>
-
@janTatesa Tatesa Uradnik <taduradnik@gmail.com>
-
@matt-snider Matt Snider <matt.snider@protonmail.com>