# Woodpecker CI 3.19 moves agent trust rules to the server and fixes clone-step environment injection

Woodpecker CI 3.19 adds server-enforced filters so workers cannot claim their way into restricted pipelines, and fixes unintended matrix-variable injection into the default clone step. Self-hosted CI operators should upgrade and review agent trust boundaries.

Woodpecker's agent labels were self-reported and unsuitable for authorization. Version 3.19 adds server-held filters and patches a clone-step environment-variable leak; administrators should verify their worker policies.

- Status: Active
- Published: 2026-10-10T12:26:53+13:00
- Updated: 2026-10-10T12:26:53+13:00
- Categories: Cloud & Infrastructure, Deployment & DevOps
- Tags: CI/CD, open source, security
- Canonical HTML: https://beyondthe.news/dossiers/woodpecker-ci-3-19-server-agent-filters-clone-env-security

## What changed

On October 7, 2026, the Woodpecker CI project released 3.19.0 with two security-relevant changes. Server-side agent filters are now stored in the Woodpecker server database and evaluated whenever an agent requests a workflow, rather than relying solely on labels reported by the agent itself. The release also fixes an unintended path where matrix environment variables were injected into the default clone step because an environment-populated clone container was no longer identified as a plugin. The upstream release credits a security report and links to merged fix PR #7157; it does not establish a public CVE or observed exploitation.

## Why it matters

A self-hosted CI server may run jobs across machines with different access to credentials, private repositories, internal networks or deployment environments. Self-reported worker labels are useful for routing but not for restricting which jobs a potentially untrusted worker can accept. The new server-side filters make that restriction a server decision. Separately, clone steps handle repository access and should not receive unrelated matrix configuration implicitly. For small teams operating mixed trusted and ephemeral runners, these are practical boundary changes, not cosmetic release features.

## Worker labels no longer have to double as authorization

Woodpecker's own documentation states that WOODPECKER_AGENT_LABELS values come from the agent and can be claimed arbitrarily. New agent filters are held on the server and applied to each workflow request. They accept key=value, key=* and mandatory !key=value syntax. If a server filter and agent label share a key, the server filter wins. Organization and personal agents additionally receive a mandatory org-id filter, preventing them from picking up another organization's workflows.

## Administrators configure filters, not the runner

Filters are edited in the server UI under instance, organization or user agent settings. A change takes effect the next time that worker requests a workflow. Administrators should assign restrictions based on real trust zones, verify which labels jobs request and test that an agent with spoofed local labels still cannot accept prohibited work. The new mechanism restricts scheduling; it does not by itself sandbox code running on a permitted worker.

## The default clone step had an environment-isolation regression

The merged fix PR #7157 explains that a clone container's Environment field was no longer empty, so the IsPlugin() check returned false and matrix variables were injected. The 3.19 release stops this injection into the default clone step. This is relevant where pipeline matrix values contain sensitive or unexpected configuration, although the published material does not demonstrate credential theft or exploitation in the wild.

## An upgrade with a concrete checklist

Upgrade Woodpecker server and agents in a tested maintenance window, review server-side filters for restricted workers, audit pipelines that previously depended on implicit matrix variables in clone behaviour, and verify intended repository access and pipeline placement. The 3.18 release had already changed how variables flow into plugins; do not assume every plugin or clone environment retains older implicit values. Keep separate secrets handling and worker isolation controls in place.

## Key details

- Woodpecker CI 3.19.0 was released October 7, 2026.
- Server-side agent filters are held in the server database, not reported by the agent.
- Filters are applied whenever an agent requests a workflow; agent labels cannot override them.
- Filter syntax includes key=value, key=* and mandatory !key=value.
- Organization and personal agents receive an additional enforced org-id restriction.
- A security fix prevents matrix environment variables from reaching the default clone step inadvertently.
- Merged upstream fix PR #7157 documents the IsPlugin() classification regression.
- The release does not document a CVE identifier or known exploitation.

## Builder takeaways

- Upgrade Woodpecker CI if you use untrusted, shared or differentiated build agents.
- Use server-side filters for authorization-sensitive worker placement; treat agent-reported labels as routing hints.
- Test that spoofing WOODPECKER_AGENT_LABELS cannot bypass server-held filters.
- Audit clone-step and plugin environment variables for unexpected exposure or reliance on implicit injection.
- Remember that server filters are scheduling controls, not isolation of code once it reaches a permitted runner.

## What to watch

- Whether maintainers publish a formal advisory or CVE and affected-version range for the clone-step bug.
- Operational feedback on server-filter migrations and policy mistakes.
- Additional runner identity hardening and scheduling constraints.
- Any compatibility notes for heterogeneous server/agent upgrades.

## Uncertainties

- No upstream evidence found for in-the-wild exploitation or a published CVE for the clone-step issue.
- The exact earliest vulnerable version and all affected deployment configurations are not established in the release notes.
- Independent production testing of server-filter enforcement has not been published in the inspected sources.

## Sources

- [Woodpecker CI 3.19.0 release notes](https://github.com/woodpecker-ci/woodpecker/releases/tag/v3.19.0) — Woodpecker CI maintainers · primary release notes · 2026-10-07T00:00:00+13:00. Release date, server-enforced agent labels, clone-step security fix and other changes.
- [Prevent injection of matrix env vars into default clone step — PR #7157](https://github.com/woodpecker-ci/woodpecker/pull/7157) — Woodpecker CI contributors · primary code change · 2026-09-17T00:00:00+12:00. Merged fix and explanation of the clone-container IsPlugin regression.
- [Agent configuration: agent filters](https://woodpecker-ci.org/docs/next/administration/configuration/agent) — Woodpecker CI documentation · primary documentation · 2026-10-10T00:00:00+13:00. Filter storage, precedence, UI paths, per-request enforcement and mandatory organization restriction.
- [Woodpecker CI 3.19 adds server-enforced agent labels](https://linuxiac.com/woodpecker-ci-3-19-adds-server-enforced-agent-labels/) — Linuxiac · specialist reporting · 2026-10-09T00:00:00+13:00. Independent specialist radar; primary upstream sources govern exact claims.

