← Voltar à pesquisa de CVEs

CVE-2026-45406

Dokku

Descrição

Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app-s openresty/http-includes/ git repository directory to the host and then interpolates their filenames, unescaped, into a single-quoted shell string that is later parsed by eval. A filename containing a single quote breaks the quoting and allows command substitution to execute arbitrary commands on the host as the dokku user during the app-s next deploy. This vulnerability is fixed in 0.38.2.

CVSS 9EPSS 0.27999999999999997%Risco 0.92
Ver fonte
Publicação
2026-06-26 17:16:33
Versões afetadas
<0.38.2
Tipo
Aplicação web
Vetor
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H