PT-2025-29520 · Dokploy · Dokploy
Mezotv
·
Published
2025-07-14
·
Updated
2025-07-17
·
CVE-2025-53825
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dokploy versions prior to 0.24.3
Description
Dokploy is a free, self-hostable Platform as a Service (PaaS). A vulnerability in the preview deployment feature allows any user to execute arbitrary code and access sensitive environment variables by opening a pull request on a public repository without authentication. This exposes secrets and potentially enables remote code execution, putting all public Dokploy users utilizing these preview deployments at risk.
Recommendations
Update Dokploy to version 0.24.3 or later.
Exploit
Fix
RCE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dokploy