🔐 CVE Alert

CVE-2026-47174

UNKNOWN 0.0

Duck Site: Untrusted pull request code can trigger privileged production deployment

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. The build workflow runs on pull requests, while the deploy workflow runs with package-write permissions and deployment secrets. If an attacker can make a pull request build satisfy the deploy workflow’s main branch condition, the deploy job checks out the triggering workflow commit, builds it into a Docker image, pushes it as latest, and triggers Dokploy deployment. This can allow attacker-controlled pull request code to become the deployed production site image without being merged. This issue has been patched in version 1.0.1.

CWE CWE-829
Vendor duck-organization
Product duck-site
Published Jun 11, 2026
Stay Ahead of the Next One

Get instant alerts for duck-organization duck-site

Be the first to know when new unknown vulnerabilities affecting duck-organization duck-site are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

duck-organization / duck-site
< 1.0.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/duck-organization/duck-site/security/advisories/GHSA-qj93-7xrg-rvhw