Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Woodpecker-ci
Woodpecker-ci woodpecker |
|
| Vendors & Products |
Woodpecker-ci
Woodpecker-ci woodpecker |
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's gRPC layer allowed any authenticated agent to impersonate any other agent on the same server by injecting a forged `agent_id` value into outgoing gRPC metadata. The server correctly verified the JWT token but then discarded the verified agent identity in favor of the client-supplied value. Version 3.14.1 patches the issue. As a workaround, disable org agents (`WOODPECKER_DISABLE_USER_AGENT_REGISTRATION=true`) and delete existing ones. | |
| Title | Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation | |
| Weaknesses | CWE-290 CWE-639 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-18T16:10:41.914Z
Reserved: 2026-06-03T18:49:32.275Z
Link: CVE-2026-50141
Updated: 2026-06-18T15:21:44.965Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-18T19:15:02Z