VYPR

Tugtainer

by Quenary

Source repositories

CVEs (3)

  • CVE-2026-47752CriJul 23, 2026
    risk 0.00cvss 9.9epss 0.00

    Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The `title_template` and `body_template` fields are rendered using an unsandboxed…

  • CVE-2026-23846HigJan 19, 2026
    risk 0.00cvss 8.1epss 0.00

    Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password authentication mechanism transmits passwords via URL query parameters instead of the HTTP request body. This causes passwords to be logged in server access logs…

  • CVE-2025-69201CriDec 29, 2025
    risk 0.00cvss 9.8epss 0.00

    Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary arguments can be injected in tugtainer-agent `POST api/command/run`. Version 1.15.1 fixes the issue.