9
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Description
Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, > or ; - can break out of the Docker container and execute commands on the host as the Dokku user. This vulnerability is fixed in 0.38.7.
AI Analysis
OS command injection vulnerability via app.json managed cron
Basic Information
ID
CVE-2026-54636
Source
GitHub_M
Published
Jun 26, 2026 at 16:23
Affected Product
Vendor
dokku
Product
dokku
Version
< 0.38.7
Affected Versions
dokku dokku < 0.38.7
CWE Classification
AI Assessment
AI Score
9 / 10
AI Severity
Critical
Vendor
Dokku
Product
Dokku
Version
< 0.38.7