CVE-2026-45405Patch(dokku / dokku)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch dokku dokku systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/zip archives into temporary directories without sanitizing member paths or preventing symlink traversal. GNU tar creates symlinks during extraction and follows them for subsequent entries, allowing an attacker to write arbitrary files anywhere writable by the dokku user — including overwriting ~/.ssh/authorized_keys to gain unrestricted shell access. This vulnerability is fixed in 0.38.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dokku

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-06-27)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
dokku

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-26: 1Mentions · 2026-06-27: 2Patch / Workaround · 2026-06-27: 2Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 206-2606-27
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-06-261
Disclosure1
2026-06-272
Patch2
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-45405 Arbitrary File Write via Symlink Traversal in Dokku Prior to 0.38.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-45405

    Post summary

    The text announces CVE-2026-45405 as an arbitrary file write vulnerability through symlink traversal in Dokku versions before 0.38.2, offering technical details but no evidence of exploits, patch, or active use.

    0001198
    4.1K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 CRITICAL - Dokku archive extraction path traversal & symlink overwrite (CVE-2026-45405) Dokku versions prior to 0.38.2 improperly extract user-supplied tar/zip archives in the git:from-archive and certs:add commands without sanitizing file paths or blocking symlink traversal. The root cause is a path traversal/symlink-following flaw during archive extraction (GNU tar can create symlinks and later entries can write through them). An attacker can exploit this by providing a crafted archive that includes symlinks and traversal paths, requiring only the ability to invoke these Dokku commands or supply an archive to a privileged operator/automation. Impact is arbitrary file write as the dokku user, including overwriting ~/.ssh/authorized_keys to gain persistent shell access and potentially pivot further. 👉 Affected: dokku < 0.38.2 | Upgrade to 0.38.2

    Post summary

    The post discloses a critical Dokku directory traversal vulnerability that permits arbitrary file writes and urges users to upgrade to version 0.38.2 for patching.

    0000082
    231 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-45405 in Dokku (CVSS 9.0) Path traversal in git:from-archive &amp; certs:add commands allows arbitrary file writes, including SSH key overwrites for shell access. Affected: &lt;0.38.2 Patch: Upgrade to 0.38.2 #CVE #Vulnerability #PatchNow https://t.co/UjJLAYsWK2

    Post summary

    The post alerts users to a critical path‑traversal flaw in Dokku (CVE-2026-45405) and recommends an immediate upgrade to version 0.38.2 as the fix.

    0000058
    52 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdokkudokku---

Explore more