Impact
Webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to version 1.22.0, deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParamsToShellVars in pkg/api/index.go into the hook script environment without an allowlist. If an upstream reverse proxy did not strip a client-supplied X-WebAuthn-User header and a hook script trusted that variable for identity or privilege, a remote unauthenticated attacker could spoof another user, bypass script security controls, and access or modify resources available to the impersonated identity.
Affected Systems
The affected software is webhookd by ncarlier. Any deployment running a version older than 1.22.0 is susceptible unless the reverse proxy has been configured to strip or sanitize the X-WebAuthn-User header. No other products are listed as affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of <1% indicates. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an unauthenticated client able to send arbitrary HTTP headers, which is feasible over the public internet. The vulnerability can be exploited remotely with minimal effort, so administrators should consider it a reasonable risk if the server is exposed and not patched.
OpenCVE Enrichment
Github GHSA