
A read-only Dokploy permission is all it takes to get root on the container (CVSS 9.9). CVE-2026-93425 lets any authenticated org member with just service:read access inject shell metacharacters into a repository path, running arbitrary commands as root. Because the standard deployment mounts the Docker socket, that's root on the container plus control of Docker and everything it manages. Fixed in Dokploy 0.29.13. Details: http://vulntracker.io/cves/CVE-2026-93425 #Dokploy #CVE #InfoSec #CyberSecurity
