PT-2025-29520 · Dokploy · Dokploy

·

CVE-2025-53825

·

Published

2025-07-14

·

Updated

2025-07-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dokploy versions prior to 0.24.3
Description Dokploy is a free, self-hostable Platform as a Service (PaaS). A vulnerability in the preview deployment feature allows any user to execute arbitrary code and access sensitive environment variables by opening a pull request on a public repository without authentication. This exposes secrets and potentially enables remote code execution, putting all public Dokploy users utilizing these preview deployments at risk.
Recommendations Update Dokploy to version 0.24.3 or later.

Exploit

Fix

RCE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-53825
GHSA-H67G-MPQ5-6PH5

Affected Products

Dokploy