CVE-2026-93425
9.9 CRITICALpublic exploit availablePublished 2026-09-24 · Updated 2026-09-24
AI risk analysis
- Summary
- The flaw allows an authenticated organization member to inject shell metacharacters into the repoPath parameter, executing arbitrary commands as root within the Dokploy container. This can lead to full host compromise.
- Exploitability
- Exploitation is relatively straightforward for an attacker with service:read permission. The attacker must first authenticate and then craft a malicious repoPath value.
- Blast radius
- If exploited, the attacker can gain root access to the host and potentially compromise other managed applications, leading to significant damage.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to version 0.29.13 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/server/src/services/patch-repo.ts without safe argument quoting. An authenticated organization member with service:read permission can inject shell metacharacters into repoPath and execute arbitrary commands through child_process.exec as root in the Dokploy container. The supplied service identifier is used only to resolve the server and does not constrain repoPath. Because the standard deployment mounts /var/run/docker.sock, container-root command execution can be used to control Docker and compromise the host and its managed applications. This issue is fixed in version 0.29.13.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-78
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-100852PoC
- CRITICALCVE-2026-103056PoC
- HIGHCVE-2026-17102
- CRITICALCVE-2026-43641
- HIGHCVE-2026-55897PoC
- HIGHCVE-2026-62182PoC
- HIGHCVE-2026-62371PoC
- CRITICALCVE-2026-66902PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.