Dockhand CVE-2026-53988: CVSS 10.0 unauthenticated webhook auth bypass
In Dockhand versions before 1.0.40, git webhook endpoints skip authentication entirely when the webhook secret is null, which is the default configuration. An unauthenticated attacker who can reach the endpoint and enumerate a stack ID can force arbitrary redeployments, and with write access to the tracked branch could push a malicious docker-compose.yml with privileged bind mounts to escape the container. Fix: upgrade to Dockhand 1.0.40 and set a strong webhook secret.
- Affects Dockhand versions before 1.0.40, rated CVSS 10.0
- Auth is skipped entirely when the webhook secret is null
- Impact ranges from DoS to container escape and host compromise
- Fix: upgrade to 1.0.40, set a strong secret, restrict webhook access
Read next
Security