CVE-2026-108584
Received Received - Intake

Hard-Coded Credentials in FunnyWolf Viper

Vulnerability report for CVE-2026-108584, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulDB

Description

A security flaw has been discovered in FunnyWolf Viper up to 3.1.11. The affected element is an unknown function of the file /root/viper/.git/config. Performing a manipulation results in hard-coded credentials. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 12 associated CPEs
Vendor Product Version / Range
FunnyWolf Viper 3.1.0
FunnyWolf Viper 3.1.1
FunnyWolf Viper 3.1.2
FunnyWolf Viper 3.1.3
FunnyWolf Viper 3.1.4
FunnyWolf Viper 3.1.5
FunnyWolf Viper 3.1.6
FunnyWolf Viper 3.1.7
FunnyWolf Viper 3.1.8
FunnyWolf Viper 3.1.9
FunnyWolf Viper 3.1.10
FunnyWolf Viper 3.1.11

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.
CWE-259 The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a hard-coded credential leak in the FunnyWolf Viper software up to version 3.1.11. The issue stems from a .git/config file in the Docker image that contains plaintext Alibaba Cloud Codeup credentials. Attackers can exploit this by downloading the public Docker image, extracting its layers, and accessing the exposed credentials to gain unauthorized access.

Detection Guidance

Check Docker images for the vulnerable viperplatform/viper:latest image by running 'docker images | grep viperplatform/viper'. Inspect the image layers for a .git/config file using 'docker save viperplatform/viper:latest | tar -xO */layer.tar | tar -tzf - | grep .git/config'. If found, extract and examine the file for plaintext credentials.

Impact Analysis

If you use the vulnerable FunnyWolf Viper Docker image, attackers could gain Admin-level access to private repositories under the FunnyWolf organization. This may lead to supply-chain attacks, unauthorized code modifications, or theft of sensitive data. Environments using the compromised image should be treated as potentially compromised.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles or HIPAA's security requirements for protected health information. Organizations may face compliance breaches, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Stop using the vulnerable viperplatform/viper:latest image immediately. Revoke any exposed Alibaba Cloud Codeup credentials. Rebuild the image without the .git directory using a .dockerignore file. Monitor for unauthorized access to repositories and audit for potential supply-chain attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108584. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart