Command Injection Vulnerability in Dokploy PaaS by Dokploy
CVE-2026-93425
What is CVE-2026-93425?
Dokploy is a user-friendly Platform as a Service (PaaS) solution that allows for flexible deployment. Prior to version 0.29.13, it contained a critical vulnerability in the patch.readRepoDirectories tRPC procedure. This flaw permitted authenticated users with specific permissions to inject shell metacharacters into the repoPath parameter used in a shell command. As a result, attackers could execute arbitrary commands with root privileges within the Dokploy container, accessing sensitive elements like the Docker socket to control host operations and compromise managed applications. This vulnerability has been addressed in version 0.29.13, emphasizing the importance of keeping software updated to safeguard against exploitation.
Affected Version(s)
dokploy < 0.29.13
