Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability exists in Dokploy, a self-hosted Platform as a Service, that allows an authenticated user with read permissions to execute arbitrary commands as root within the container. This could lead to full compromise of the host system and its managed applications. The issue is addressed in version 0.29.13.
- Code execution flaw in a management platform.
- Could grant an attacker full system control.
- Confirm if this self-hosted service is in use.
Attack Path
How an attacker could exploit the issue
An attacker with authenticated access to Dokploy can exploit a vulnerability in how repository paths are handled. By injecting special characters into a repository path, an attacker can trick the system into executing arbitrary commands on the server. Because Dokploy often runs with access to the Docker socket, this command execution can be escalated to control Docker and compromise the entire host system and any applications it manages.
- Authenticated organization member with service:read permission.
- Injecting shell metacharacters into repoPath.
- Arbitrary command execution, container escape, and host compromise.
Live Threat
Current exploitation, exposure, and threat context
An authenticated user with read permissions for services could execute arbitrary commands as root within the Dokploy container. When Docker is also running within the container, this could lead to the compromise of the host system and any applications it manages.
- Container and host system data.
- Arbitrary command execution via a vulnerable procedure.
- Full compromise of host and managed applications.
Operational Fix
Recommended remediation, mitigation, and detection steps
Platform owners and infrastructure teams are likely responsible for addressing this vulnerability in Dokploy. The initial practical move is to locate all Dokploy instances, confirm their network exposure and business criticality, and identify the accountable owner for each. Subsequently, a remediation plan should be developed based on the identified risks.
- Platform and infrastructure teams own it.
- Verify Dokploy instance reachability and criticality.
- Plan remediation and coordinate vendor updates.