CVE WATCH / VULNERABILITY DETAIL

CVE-2026-93425

CRITICALCVSS 9.9NVD feed

Published 24 September 2026 · tracked since 25 September 2026

Description

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/server/src/services/patch-repo.ts without safe argume

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-93425 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-93425

CRITICALCVSS 9.9NVD feed

Published 24 September 2026 · tracked since 25 September 2026

Description

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/server/src/services/patch-repo.ts without safe argume

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]