VYPR
Unrated severityOSV Advisory· Published Jul 23, 2026· Updated Jul 23, 2026

Tugtainer has Server-Side Template Injection in notification templates that leads to Remote Code Execution

CVE-2026-47752

Description

Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The title_template and body_template fields are rendered using an unsandboxed jinja2.Environment, allowing any authenticated user to execute arbitrary OS commands as root inside the container. Version 1.30.2 fixes the issue.

Affected products

3
  • Quenary/TugtainerOSV2 versions
    v1.30.1, v1.30.0, v1.29.1, …+ 1 more
    • (no CPE)range: v1.30.1, v1.30.0, v1.29.1, …
    • (no CPE)range: <1.30.2
  • Range: <1.30.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.