Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in Dokploy, a platform for managing application deployments. The issue allows an authenticated user to inject operating-system commands, potentially impacting the host environment where Dokploy is running. The main concern is confirming relevance and exposure.
- Allows command injection in a deployment platform.
- Affects systems managing application deployments.
- Confirm relevance and exposure of this platform.
Attack Path
How an attacker could exploit the issue
An attacker with backup-restore permissions can inject commands into the Dokploy host system. This is possible because the backup restoration process improperly handles user-provided database names and backup file names, allowing them to be interpreted as shell commands. This could lead to complete host compromise.
- Authenticated member with backup-restore access.
- Injecting shell commands via database name or backup file fields.
- Command execution on the Dokploy host.
Live Threat
Current exploitation, exposure, and threat context
An authenticated user with backup-restore permissions could inject operating-system commands into the Dokploy host environment. This could occur through the backup restore functionality when building database restore shell pipelines, even if a valid database or backup file does not exist.
- Host system commands could be executed.
- Malicious commands injected via backup restore.
- Full system compromise may be possible.
Operational Fix
Recommended remediation, mitigation, and detection steps
Platform owners or infrastructure teams are likely responsible for addressing this critical vulnerability in Dokploy, a self-hosted PaaS. The immediate first step is to identify all Dokploy instances within your environment, confirm their external reachability and business criticality, and then locate the specific team or individual accountable for each instance to initiate a risk-based remediation plan.
- Platform owners should take immediate action.
- Verify Dokploy instance reachability and criticality.
- Plan risk-based remediation and coordinate upgrades.