PT-2026-97912 · Dokploy · Dokploy

CVE-2026-93425

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dokploy versions prior to 0.29.13
Description An authenticated organization member with service:read permission can execute arbitrary commands as root within the Dokploy container. The issue occurs because the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath variable from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/server/src/services/patch-repo.ts without safe argument quoting via child process.exec. Since standard deployments mount /var/run/docker.sock, this container-root access can be leveraged to control Docker and compromise the host system and its managed applications.
Recommendations Update to version 0.29.13.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93425
GHSA-56G6-WJR4-5Q7P

Affected Products

Dokploy