OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-93425

CRITICAL · CVSS 9.9 EPSS 0.62% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Dokploy versions prior to 0.29.13 are vulnerable to a critical command injection flaw that allows authenticated users with service:read permissions to execute arbitrary commands as root within the Dokploy container. This vulnerability can lead to complete control over the Docker daemon, potentially compromising the host and all managed applications. Organizations using Dokploy should prioritize upgrading to version 0.29.13 to mitigate this severe risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-93425
Severity
CRITICAL
CVSS
9.9
EPSS
0.62%
Docker

Original NVD Description

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/server/src/services/patch-repo.ts without safe argument quoting. An authenticated organization member with service:read permission can inject shell metacharacters into repoPath and execute arbitrary commands through child_process.exec as root in the Dokploy container. The supplied service identifier is used only to resolve the server and does not constrain repoPath. Because the standard deployment mounts /var/run/docker.sock, container-root command execution can be used to control Docker and compromise the host and its managed applications. This issue is fixed in version 0.29.13.