Description
A vulnerability was found in Laradock up to 20.4. Impacted is an unknown function of the file workspace/Dockerfile of the component Build Process. The manipulation results in download of code without integrity check. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-10-04
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: Remote code execution via code download
Action: Assess Impact
AI Analysis

Impact

The flaw in Laradock’s build process permits an adversary to remotely trigger the download of arbitrary code into the workspace Dockerfile without any integrity verification, exposing the system to the execution of malicious payloads.

Affected Systems

The vulnerability affects the Laradock project and its Dockerfiles, specifically versions up to 20.4.; any deployment using those builds is at risk.

Risk and Exploitability

With a CVSS score of 2.3 the severity is low, yet the exploit is publicly available and can be launched remotely with high complexity, making it difficult but technically feasible. The lack of an integrity check elevates the risk of unauthorized code execution, though the vulnerability is not yet listed in CISA’s KEV catalog.

Generated by OpenCVE AI on October 4, 2026 at 10:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check for and upgrade to a newer Laradock release that contains the fix.
  • If a patch is unavailable, disable or tightly restrict remote HTTP code download capabilities in the Dockerfile, for example by using signed artifacts or local mirrors.
  • Implement network isolation or firewall rules to prevent unauthorized outbound connections from the build environment.
  • Monitor system logs for unexpected code download activity to detect potential exploitation attempts.

Generated by OpenCVE AI on October 4, 2026 at 10:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Laradock up to 20.4. Impacted is an unknown function of the file workspace/Dockerfile of the component Build Process. The manipulation results in download of code without integrity check. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Laradock Build Process Dockerfile code download
First Time appeared Laradock
Laradock laradock
Weaknesses CWE-494
CPEs cpe:2.3:a:laradock:laradock:*:*:*:*:*:*:*:*
Vendors & Products Laradock
Laradock laradock
References
Metrics cvssV2_0

{'score': 5.1, 'vector': 'AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 5, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Laradock Laradock
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-04T07:30:11.180Z

Reserved: 2026-10-03T13:24:26.683Z

Link: CVE-2026-105137

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T09:16:38.970

Modified: 2026-10-04T09:16:38.970

Link: CVE-2026-105137

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T10:30:09Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check