CVE-2026-93425

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/server/src/services/patch-repo.ts without safe argument quoting. An authenticated organization member with service:read permission can inject shell metacharacters into repoPath and execute arbitrary commands through child_process.exec as root in the Dokploy container. The supplied service identifier is used only to resolve the server and does not constrain repoPath. Because the standard deployment mounts /var/run/docker.sock, container-root command execution can be used to control Docker and compromise the host and its managed applications. This issue is fixed in version 0.29.13.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-24: 109-24
Referenced assets1 URL
By indicator
Full discourse1 post
  • VulnTracker@vuln_tracker

    A read-only Dokploy permission is all it takes to get root on the container (CVSS 9.9). CVE-2026-93425 lets any authenticated org member with just service:read access inject shell metacharacters into a repository path, running arbitrary commands as root. Because the standard deployment mounts the Docker socket, that's root on the container plus control of Docker and everything it manages. Fixed in Dokploy 0.29.13. Details: http://vulntracker.io/cves/CVE-2026-93425 #Dokploy #CVE #InfoSec #CyberSecurity

    10020179
    765 followersView on X

Explore more