CVE-2026-47752: Tugtainer has Server-Side Template Injection in notification templates that leads to Remote Code Execution
Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The titletemplate and bodytemplate fields are rendered using an unsandboxed jinja2.Environment, allowing any authenticated user to execute arbitrary OS commands as root inside the container. Version 1.30.2 fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tugtainerto a version that resolves this vulnerability.Fixed in 1.30.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47752?
CVE-2026-47752 has a critical severity score of 9.9.
What does CVE-2026-47752 affect?
CVE-2026-47752 affects Tugtainer versions prior to 1.30.2.
What type of vulnerability is CVE-2026-47752?
CVE-2026-47752 is a Server-Side Template Injection (SSTI) vulnerability.
How do I fix CVE-2026-47752?
To fix CVE-2026-47752, update Tugtainer to version 1.30.2 or later.
What can exploit CVE-2026-47752?
CVE-2026-47752 can be exploited to achieve Remote Code Execution.