Vulnerabilities (CVE)

Filtered by vendor Dokploy Subscribe
Filtered by product Dokploy
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-53825 1 Dokploy 1 Dokploy 2025-09-11 N/A 9.4 CRITICAL
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deployment vulnerability in Dokploy allows any user to execute arbitrary code and access sensitive environment variables by simply opening a pull request on a public repository. This exposes secrets and potentially enables remote code execution, putting all public Dokploy users using these preview deployments at risk. Version 0.24.3 contains a fix for the issue.