PT-2026-48713 · Dokploy+1 · Dokploy+1
CVE-2026-47174
·
Published
2026-06-11
·
Updated
2026-06-11
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Duck Site versions prior to 1.0.1
Description
A flaw exists in the deploy workflow that executes following the build workflow. While the build workflow is triggered by pull requests, the deploy workflow possesses package-write permissions and deployment secrets. An attacker can manipulate a pull request build to satisfy the main branch condition of the deploy workflow. This allows the deploy job to check out the commit from the triggering workflow, build it into a Docker image, push it as the latest version, and trigger a Dokploy deployment. Consequently, attacker-controlled code from a pull request can be deployed as the production site image without being merged into the main branch.
Recommendations
Update to version 1.0.1.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dokploy
Duck-Site