PT-2026-48713 · Dokploy+1 · Dokploy+1

CVE-2026-47174

·

Published

2026-06-11

·

Updated

2026-06-11

CVSS v4.0

9.5

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Duck Site versions prior to 1.0.1
Description A flaw exists in the deploy workflow that executes following the build workflow. While the build workflow is triggered by pull requests, the deploy workflow possesses package-write permissions and deployment secrets. An attacker can manipulate a pull request build to satisfy the main branch condition of the deploy workflow. This allows the deploy job to check out the commit from the triggering workflow, build it into a Docker image, push it as the latest version, and trigger a Dokploy deployment. Consequently, attacker-controlled code from a pull request can be deployed as the production site image without being merged into the main branch.
Recommendations Update to version 1.0.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47174
GHSA-QJ93-7XRG-RVHW

Affected Products

Dokploy
Duck-Site