Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a vulnerability in Dokploy, a self-hostable platform used for managing application deployments. The issue allows certain users within an organization to access sensitive Git provider credentials, such as API tokens and secrets, even without explicit permissions. This could potentially enable unauthorized access to private code repositories or manipulation of external development workflows.
- Stolen credentials could expose private code.
- Affects self-hosted deployment management services.
- Confirm exposure and relevance for security review.
Attack Path
How an attacker could exploit the issue
An attacker with an organization membership in Dokploy can retrieve sensitive Git provider credentials. This occurs because specific API endpoints expose full provider details without proper access controls, even when the member lacks direct Git provider access. The vulnerability allows bypassing per-member assignments, enabling the attacker to use the exposed credentials to access private code repositories or alter external automated workflows.
- Organization membership required.
- Exposed Git provider credentials.
- Access to private code and workflows.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, organization members without Git provider access could retrieve plaintext provider credentials and GitHub App private keys. This could enable unauthorized access to private repositories or manipulation of external workflows.
- Git provider credentials and private keys.
- Through protected procedures and routes.
- Unauthorized repository access or workflow manipulation.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts Dokploy PaaS deployments, potentially exposing Git provider credentials and GitHub App private keys to unauthorized organization members. The first step is to identify all Dokploy instances, confirm their network exposure and business criticality, and then locate the accountable owner for remediation planning.
- Platform/Application owners should investigate.
- Verify Dokploy instance exposure and criticality.
- Plan remediation based on identified risk.