CVE 9 CRITICAL

Dokku: OS Command Injection via app.json managed Cron_CVE-2026-54636

9 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Description

Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, > or ; - can break out of the Docker container and execute commands on the host as the Dokku user. This vulnerability is fixed in 0.38.7.

AI Analysis

OS command injection vulnerability via app.json managed cron

Basic Information

ID CVE-2026-54636
Source GitHub_M
Published Jun 26, 2026 at 16:23

Affected Product

Vendor dokku
Product dokku
Version < 0.38.7
Affected Versions dokku dokku < 0.38.7

CWE Classification

AI Assessment

AI Score 9 / 10
AI Severity Critical
Vendor Dokku
Product Dokku
Version < 0.38.7

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.