Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93425— Dokploy: Authenticated OS Command Injection in patch.readRepoDirectories (repoPath) leads to RCE as root

Quick assessment

Affected
Dokploy dokploy
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Dokploy 是一个免费、可自托管的平台即服务(PaaS)系统。在 0.29.13 版本之前, tRPC 接口将来自 中用户可控的 值直接传入 中的 shell 命令,且未对参数进行安全的引号转义或过滤。 拥有 权限的已认证组织成员可通过在 中注入 shell 元字符,利用 在 Dokploy 容器内以 root 权限执行任意命令。所提供的服务标识符仅用于解析对应的服务器,并不能对 的值施加任何限制。 由于标准部署方式会挂载 ,攻击者可利用容器内的 root 权限执行命令来操控 Docker 守护进程,进而攻破宿

CVSS 9.9 · Critical EPSS 0.62% · P48

Affected Version Matrix 1

VendorProduct Version RangeStatus
Dokploy dokploy < 0.29.13 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93425

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Dokploy: Authenticated OS Command Injection in patch.readRepoDirectories (repoPath) leads to RCE as root
Source: CVE Program / CVE List V5
Vulnerability Description
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/server/src/services/patch-repo.ts without safe argument quoting. An authenticated organization member with service:read permission can inject shell metacharacters into repoPath and execute arbitrary commands through child_process.exec as root in the Dokploy container. The supplied service identifier is used only to resolve the server and does not constrain repoPath. Because the standard deployment mounts /var/run/docker.sock, container-root command execution can be used to control Docker and compromise the host and its managed applications. This issue is fixed in version 0.29.13.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Dokploy dokploy < 0.29.13 -

II. Public POCs for CVE-2026-93425

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93425

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-93425 (1)

Vendor Advisories for CVE-2026-93425 (1)

Vendor Pages for CVE-2026-93425 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-93425

No comments yet


Leave a comment