CVE-2026-105137
Received Received - Intake

Remote Code Download Without Integrity Check in Laradock

Vulnerability report for CVE-2026-105137, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulDB

Description

A vulnerability was found in Laradock up to 20.4. Impacted is an unknown function of the file workspace/Dockerfile of the component Build Process. The manipulation results in download of code without integrity check. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
laradock laradock to 20.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-494 The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105137 is a build-time Remote Code Execution (RCE) vulnerability in Laradock versions up to v20.4. It occurs when Docker images are built by downloading third-party dependencies over insecure HTTP without integrity checks. Attackers in a network position can replace these downloads with malicious code, which executes as root during the build process. This creates persistent backdoors in the final Docker images.

Detection Guidance

Check Dockerfiles in Laradock for HTTP downloads without integrity checks. Inspect network traffic for unencrypted downloads of dependencies like event-3.0.6.tgz or New Relic agent. Use tools like Wireshark or tcpdump to monitor for plain HTTP requests to external domains during Docker builds.

Impact Analysis

This vulnerability allows attackers to compromise Docker images during build, leading to persistent backdoors in production environments. It can result in unauthorized code execution, data breaches, or full system compromise. Exploitation requires no authentication and leaves minimal traces, making it difficult to detect.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR and HIPAA requirements for data protection and integrity. Organizations using affected Laradock versions may face compliance violations, legal penalties, and reputational damage due to compromised systems handling sensitive data.

Mitigation Strategies

Replace HTTP downloads with HTTPS in Dockerfiles. Pin SHA-256 checksums for downloaded dependencies. Use private repositories with authentication for third-party packages. Enable Docker content trust and verify image integrity post-build.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105137. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart