CVE-2026-105137
Last modified
CVE-2026-105137 is a medium-severity vulnerability rated 5/10 on the CVSS scale. A vulnerability was found in Laradock up to 20.4. Impacted is an unknown function of the file workspace/Dockerfile of the component Build Process.
Description
A vulnerability was found in Laradock up to 20.4. Impacted is an unknown function of the file workspace/Dockerfile of the component Build Process. The manipulation results in download of code without integrity check. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | Laradock | 20.0; 20.1; 20.2; 20.3; 20.4 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-105137?
How severe is CVE-2026-105137?
How do I fix CVE-2026-105137?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10513The Webmention plugin for WordPress is vulnerable to Stored …7.2
- CVE-2026-105130LaraDashboard from 1.4.0 before 1.4.8 contains a race condit…3.7
- CVE-2026-105131ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escala…5.4
- CVE-2026-105133A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2.…7.3
- CVE-2026-105134A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This v…10
- CVE-2026-105135A vulnerability has been found in InternLM MindSearch 0.1.0.…10
- CVE-2026-10514A vulnerability has been found in 1Panel-dev CordysCRM up to…2.4
- CVE-2026-105141A security flaw has been discovered in topoteretes cognee up…6.3
- CVE-2026-105144A flaw has been found in Drogon up to 1.9.13-1/10.0-beta.3 o…5.3
- CVE-2026-105145A vulnerability has been found in Weaviate Verba up to 2.1.3…5.3
- CVE-2026-105146A vulnerability was found in Comsenz Discuz! X5.0-20260801/X…4.7
- CVE-2026-105147A vulnerability was determined in SciPhi-AI R2R up to 3.6.6.…7.3
Are you affected by CVE-2026-105137?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
