Advisories for Golang/Github.com/Woodpecker-Ci/Woodpecker package

2026

Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend

A privilege escalation vulnerability affects Woodpecker instances using the Kubernetes backend. The pipeline option backend_options.kubernetes.serviceAccountName was passed directly to the pod spec without any admin gating. Who is impacted: any operator running the Kubernetes backend. Any user with Push permission on a connected repository can run pipeline pods under an arbitrary ServiceAccount in the pipeline namespace, gaining that account's RBAC permissions. If a privileged ServiceAccount is reachable in that namespace, …

2023

Improper Input Validation

Woodpecker is a community fork of the Drone CI system. In affected versions an attacker can post malformed webhook data witch lead to an update of the repository data that can e.g. allow the takeover of an repo. This is only critical if the CI is configured for public usage and connected to a forge witch is also in public usage. This issue has been addressed in version 1.0.2. Users …

2022