Description
webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParamsToShellVars in pkg/api/index.go into the hook script environment without an allowlist. When an upstream reverse proxy did not strip a client-supplied X-WebAuthn-User header and a hook script trusted that variable for identity or privilege, a remote unauthenticated attacker could spoof another user, bypass script security controls, and access or modify resources available to the impersonated identity. This issue is fixed in version 1.22.0.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Uncontrolled shell variable injection via HTTP headers allows an unauthenticated attacker to spoof user identity and gain unauthorized access to resources
Action: Patch to v1.22.0
AI Analysis

Impact

Webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to version 1.22.0, deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParamsToShellVars in pkg/api/index.go into the hook script environment without an allowlist. If an upstream reverse proxy did not strip a client-supplied X-WebAuthn-User header and a hook script trusted that variable for identity or privilege, a remote unauthenticated attacker could spoof another user, bypass script security controls, and access or modify resources available to the impersonated identity.

Affected Systems

The affected software is webhookd by ncarlier. Any deployment running a version older than 1.22.0 is susceptible unless the reverse proxy has been configured to strip or sanitize the X-WebAuthn-User header. No other products are listed as affected.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score of <1% indicates. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an unauthenticated client able to send arbitrary HTTP headers, which is feasible over the public internet. The vulnerability can be exploited remotely with minimal effort, so administrators should consider it a reasonable risk if the server is exposed and not patched.

Generated by OpenCVE AI on September 20, 2026 at 15:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade webhookd to release 1.22.0 or later, which removes the unfiltered environment variable creation
  • If an upgrade is delayed, configure the reverse proxy to strip or sanitize any client‑supplied X-WebAuthn‑User headers before forwarding requests to webhookd
  • Audit hook scripts to ensure they do not rely on potentially tainted header values for authentication or privilege decisions

Generated by OpenCVE AI on September 20, 2026 at 15:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-v25g-mvwr-f5fp webhookd: Unrestricted HTTP Header to Shell Variable Injection
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ncarlier
Ncarlier webhookd
Vendors & Products Ncarlier
Ncarlier webhookd

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParamsToShellVars in pkg/api/index.go into the hook script environment without an allowlist. When an upstream reverse proxy did not strip a client-supplied X-WebAuthn-User header and a hook script trusted that variable for identity or privilege, a remote unauthenticated attacker could spoof another user, bypass script security controls, and access or modify resources available to the impersonated identity. This issue is fixed in version 1.22.0.
Title webhookd: Unrestricted HTTP Header to Shell Variable Injection
Weaknesses CWE-290
CWE-807
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ncarlier Webhookd
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:38:42.407Z

Reserved: 2026-07-02T16:50:27.887Z

Link: CVE-2026-59157

cve-icon Vulnrichment

Updated: 2026-09-16T15:38:38.935Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:16.957

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-59157

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:00:14Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision