External risk intelligence

Dokploy Command Injection via Unquoted Shell Argument leads to Host Compromise.

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-93425

Dokploy is a self-hosted Platform as a Service (PaaS) designed to manage deployments and applications. As a web-based management platform, it is commonly deployed as an internet-facing service or an accessible administrative portal for managing application infrastructure, placing it in a position where network exposure is a common and intended deployment pattern.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability exists in Dokploy, a self-hosted Platform as a Service, that allows an authenticated user with read permissions to execute arbitrary commands as root within the container. This could lead to full compromise of the host system and its managed applications. The issue is addressed in version 0.29.13.

  • Code execution flaw in a management platform.
  • Could grant an attacker full system control.
  • Confirm if this self-hosted service is in use.

Attack Path

How an attacker could exploit the issue

An attacker with authenticated access to Dokploy can exploit a vulnerability in how repository paths are handled. By injecting special characters into a repository path, an attacker can trick the system into executing arbitrary commands on the server. Because Dokploy often runs with access to the Docker socket, this command execution can be escalated to control Docker and compromise the entire host system and any applications it manages.

  • Authenticated organization member with service:read permission.
  • Injecting shell metacharacters into repoPath.
  • Arbitrary command execution, container escape, and host compromise.

Live Threat

Current exploitation, exposure, and threat context

An authenticated user with read permissions for services could execute arbitrary commands as root within the Dokploy container. When Docker is also running within the container, this could lead to the compromise of the host system and any applications it manages.

  • Container and host system data.
  • Arbitrary command execution via a vulnerable procedure.
  • Full compromise of host and managed applications.

Operational Fix

Recommended remediation, mitigation, and detection steps

Platform owners and infrastructure teams are likely responsible for addressing this vulnerability in Dokploy. The initial practical move is to locate all Dokploy instances, confirm their network exposure and business criticality, and identify the accountable owner for each. Subsequently, a remediation plan should be developed based on the identified risks.

  • Platform and infrastructure teams own it.
  • Verify Dokploy instance reachability and criticality.
  • Plan remediation and coordinate vendor updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Dokploy?

Dokploy is an open-source, self-hosted Platform as a Service (PaaS) solution. It functions as a centralized management dashboard for containerized applications and infrastructure, allowing users to streamline deployment and scaling tasks from a unified interface.

How is the CVE-2026-93425 vulnerability classified?

This security issue is a command injection flaw, identified as CWE-78. It occurs because the software fails to sanitize user-supplied input before passing it to a system command. By not properly quoting arguments, the application allows an attacker to inject and execute malicious shell commands.

Where does the command injection trigger occur?

The flaw exists within the patch.readRepoDirectories tRPC procedure. An attacker with service:read permissions can submit a crafted repoPath. While the system uses a service identifier to locate the server, this does not restrict the path input, permitting arbitrary shell metacharacters to reach the backend execution logic.

Why is this vulnerability considered a high-risk security signal?

According to Halo Surface Signal, this vulnerability is likely to be exposed because Dokploy is designed as a web-based administrative portal, often deployed as an internet-facing service. The ability to achieve root execution inside the container, combined with standard Docker socket mounting, creates a severe risk of full host compromise.

How should organizations address this infrastructure risk?

Infrastructure teams should first conduct an inventory to locate all active Dokploy instances and determine their network exposure levels. Once identified, teams should coordinate to update the software to version 0.29.13 or later, which contains the necessary patches to safely handle repository path inputs.

References