CVE-2026-53988: Dockhand < 1.0.40 Unauthenticated Webhook Trigger via Git Webhook Endpoints
Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or, when combined with write access to the tracked git branch, container escape and full host compromise via attacker-controlled docker-compose.yml with privileged bind mounts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dockhandto a version that resolves this vulnerability.Fixed in 1.0.40
Event History
Frequently Asked Questions
Who is exposed to unauthenticated triggering?
Dockhand deployments running a version earlier than 1.0.40 are exposed if their git webhook endpoints are reachable by a remote attacker. The affected endpoints allow unsigned webhook requests because of a null webhook-secret guard condition.
What does an attacker need to escalate beyond redeployment-based denial of service?
An attacker needs write access to the git branch tracked by a target stack. They can then combine an unsigned webhook trigger with an attacker-controlled docker-compose.yml, potentially using privileged bind mounts to escape containers and compromise the host.
How can an attacker identify target stacks?
The stack IDs can be enumerated because they are sequential. An attacker can use those IDs when sending unsigned requests to trigger git clone and Docker Compose operations for target stacks.