Sceawere
Vulnerability Detail
CVE-2026-105137UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Laradock Workspace Insecure Code Download
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5
- Creation Date
- 4h ago
- Vendor
- n/a
- Product
- Laradock
- Attack Type
- Download of Code Without Integrity Check
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
A vulnerability was found in Laradock up to 20.4. Impacted is an unknown function of the file workspace/Dockerfile of the component Build Process. The manipulation results in download of code without integrity check. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.0",
"pubDate": "2026-10-04T09:16:38.970Z",
"pubdate": "2026-10-04T09:16:38.970Z",
"executiveSummary": "A critical vulnerability exists in the Laradock build process, specifically within the 'workspace/Dockerfile' component, affecting all versions up to and including 20.4.\nThe vulnerability involves the insecure retrieval of external code, where the system fails to implement mandatory integrity checks (such as cryptographic checksum verification or GPG signature validation) during the download phase.\nThis flaw allows remote attackers to perform unauthorized code injection or supply chain manipulation. By intercepting or influencing the download process, an adversary can deliver malicious payloads that are subsequently built and executed within the development environment.\nThe risk is exacerbated by the lack of vendor responsiveness following disclosure. Although the exploit is categorized as having high complexity and being difficult to execute, its public availability poses a significant threat to development pipelines and containerized infrastructure that rely on automated Laradock deployments.\nSuccessful exploitation compromises the integrity of the build process, potentially leading to persistent backdoors, data exfiltration, or the unauthorized execution of arbitrary code within the workspace container.",
"technicalDetails": "The vulnerability resides within the build logic of the 'workspace/Dockerfile' in Laradock. During the image construction phase, the Dockerfile executes instructions—typically 'curl', 'wget', or package manager commands—to fetch remote assets, dependencies, or installation scripts from external repositories or remote web servers.\nThe root cause is the absence of a 'trust-on-first-use' or 'verification-at-runtime' mechanism. Specifically, the implementation lacks hash validation (e.g., sha256sum) for the downloaded artifacts. In a standard secure software supply chain, every retrieved binary or script must be verified against a known-good cryptographic hash to ensure the integrity and authenticity of the code before execution.\nThe attack flow commences with a remote attacker identifying the specific build instructions in the 'workspace/Dockerfile' that pull external dependencies over unencrypted or insecure channels. Because these instructions do not enforce integrity checks, an attacker who can intercept the network traffic (via Man-in-the-Middle) or compromise the hosting server of the remote asset can replace the legitimate code with a malicious equivalent.\nWhen the 'docker build' process is triggered, the affected Dockerfile automatically retrieves the tainted payload. Because the container build process assumes the source is trusted, it proceeds to execute the injected code with the privileges defined by the Dockerfile context—often running as a privileged user or service account within the container environment.\nThe exploitation is deemed complex as it requires either network-level interception (e.g., DNS spoofing, BGP hijacking, or ARP poisoning) or a compromise of the third-party infrastructure hosting the dependencies. However, once the malicious payload is successfully fetched and built into the image, the impact is significant: the containerized workspace becomes a pivot point for lateral movement within the host system or the broader network.\nThe persistence of this vulnerability is absolute until the build instructions are modified to utilize immutable references or explicit integrity verification mechanisms. Post-exploitation, an attacker gains the ability to execute arbitrary commands, modify project source code within the volume mounts, or harvest environment variables, credentials, and secrets often stored in the development workspace."
}