VYPR

laradock_build_time_rce_http_download

by Laradock

CVEs (1)

  • CVE-2026-105137MedOct 4, 2026
    risk 0.33cvss 5.0epss —

    A vulnerability was found in Laradock up to 20.4. Impacted is an unknown function of the file workspace/Dockerfile of the component Build Process. The manipulation results in download of code without integrity check. The attack can be launched remotely. A high complexity level…