PT-2025-53753 · Unknown+1 · Tugtainer-Agent+1

Yasinseyhun

·

Published

2025-12-24

·

Updated

2026-02-20

·

CVE-2025-69201

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tugtainer versions prior to 1.15.1
Description Tugtainer is a self-hosted application designed for automating updates of docker containers. A flaw exists where arbitrary arguments can be injected. This occurs through the POST api/command/run endpoint of the tugtainer-agent. The api/command/run endpoint is susceptible to command injection due to improper input validation. The vulnerable parameter is not explicitly identified.
Recommendations Update Tugtainer to version 1.15.1 or later.

Exploit

Fix

RCE

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-00421
CVE-2025-69201
GHSA-GRC3-8W5X-G54Q

Affected Products

Tugtainer
Tugtainer-Agent