← Back to search

CVE-2026-93425

9.9 CRITICALpublic exploit available

Published 2026-09-24 · Updated 2026-09-24

AI risk analysis

Summary
The flaw allows an authenticated organization member to inject shell metacharacters into the repoPath parameter, executing arbitrary commands as root within the Dokploy container. This can lead to full host compromise.
Exploitability
Exploitation is relatively straightforward for an attacker with service:read permission. The attacker must first authenticate and then craft a malicious repoPath value.
Blast radius
If exploited, the attacker can gain root access to the host and potentially compromise other managed applications, leading to significant damage.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to version 0.29.13 or later.
rceauth-bypassshell-injectionpoc

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/server/src/services/patch-repo.ts without safe argument quoting. An authenticated organization member with service:read permission can inject shell metacharacters into repoPath and execute arbitrary commands through child_process.exec as root in the Dokploy container. The supplied service identifier is used only to resolve the server and does not constrain repoPath. Because the standard deployment mounts /var/run/docker.sock, container-root command execution can be used to control Docker and compromise the host and its managed applications. This issue is fixed in version 0.29.13.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-78

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.